Courseiva

CCNA Deployment Questions

75 of 254 questions · Page 2/4 · Deployment · Answers revealed

76
Multi-Selecthard

Which TWO approaches can a developer use to automate the deployment of a microservices application to Amazon ECS with Fargate, ensuring that each microservice is independently deployable and can scale based on demand?

Select 2 answers
A.Define all microservices in a single task definition and run them as one service
B.Use a single ECS service with multiple containers per task definition
C.Use a single CodePipeline that builds all microservices together
D.Define each microservice as a separate ECS service with its own task definition
E.Use a separate CodePipeline for each microservice that builds and deploys independently
AnswersD, E

Defining each microservice as a separate ECS service, each with its own dedicated task definition, is the correct architectural pattern for microservices on ECS. This approach enables independent scaling, deployment, and lifecycle management for each individual service, allowing developers to update or scale a single microservice without affecting others. It ensures optimal resource allocation and fault isolation, aligning perfectly with microservice principles.

Why this answer

Defining each microservice as a separate ECS service with its own task definition allows independent deployment, scaling, and lifecycle management. Each service can be updated, rolled back, or scaled based on its own demand without affecting other microservices, which aligns with microservices architecture principles.

Exam trap

The trap here is that candidates confuse 'multiple containers per task' (which still couples them) with 'separate services' (which decouples them), leading them to choose Option B as a valid approach for independent deployment.

77
MCQmedium

A developer is deploying a new version of a Lambda function using the AWS CLI. The developer wants to shift 10% of traffic to the new version and then gradually increase to 100% over 10 minutes. Which CLI command should the developer use?

A.aws lambda publish-version --function-name my-function
B.aws lambda create-function --function-name my-function --zip-file fileb://my-code.zip
C.aws lambda update-alias --function-name my-function --name prod --function-version 2 --routing-config AdditionalVersionWeights={"1":0.9}
D.aws lambda invoke --function-name my-function --payload '{}'
AnswerC

This command precisely implements a canary deployment strategy by updating the `prod` alias. It configures the alias to direct 10% of the invocation traffic (calculated as 1.0 minus the specified `AdditionalVersionWeights` for the older version, 0.9) to the newly specified `function-version 2`. The remaining 90% of traffic continues to serve `version 1`, allowing for gradual rollout and monitoring of the new version before a full cutover.

Why this answer

The `update-alias` command with the `--routing-config` parameter allows you to implement canary deployments by assigning a percentage of traffic to a new Lambda function version. In this case, `AdditionalVersionWeights={"1":0.9}` routes 10% of traffic to version 2 (the new version) and 90% to version 1. However, note that this command only sets a static routing configuration; to gradually increase traffic to 100% over 10 minutes, you must update the alias multiple times (e.g., via a script) to adjust the weights progressively.

The command shown is the correct initial step to start the canary deployment.

Exam trap

The trap here is that candidates may confuse `publish-version` (which only creates a version) with the alias routing command needed to actually shift traffic, or they may think `invoke` can be used for deployment, but only `update-alias` with `--routing-config` enables the weighted traffic shift described in the question.

How to eliminate wrong answers

Option A is wrong because `publish-version` only creates a new immutable version of the Lambda function but does not route any traffic to it; it requires a separate alias update to shift traffic. Option B is wrong because `create-function` is used to create a new Lambda function from scratch, not to deploy a new version or manage traffic routing for an existing function. Option D is wrong because `invoke` is used to synchronously invoke a Lambda function with a payload, not to deploy or shift traffic between versions.

78
MCQhard

A company uses AWS CodeBuild for building and testing their application. They have a build project that runs on a Linux environment. They want to run a build in a custom Docker image that is stored in Amazon ECR. How should they configure the build project?

A.Add a 'Dockerfile' to the source code and specify it in the buildspec.
B.In the environment configuration, set the 'Image' field to the ECR image URI.
C.Use a managed image provided by AWS CodeBuild.
D.Configure the pipeline to pass the image URI as an environment variable.
AnswerB

AWS CodeBuild projects allow you to define the build environment by specifying a custom Docker image. This is achieved by navigating to the "Environment" section of the CodeBuild project configuration and setting the "Image" field directly to the Amazon ECR image URI (e.g., `aws_account_id.dkr.ecr.region.amazonaws.com/repository-name:tag`). CodeBuild will then pull this specific image from ECR to execute the build commands, ensuring a consistent and controlled build environment.

Why this answer

AWS CodeBuild allows you to specify a custom Docker image from Amazon ECR by entering its URI directly in the 'Image' field under the environment configuration. This enables the build to run in a container that includes all necessary dependencies, without requiring a Dockerfile in the source code or a managed image.

Exam trap

The trap here is that candidates confuse specifying a Dockerfile to build a new image (Option A) with using an existing custom image as the build environment, leading them to overlook the direct ECR URI configuration in the environment settings.

How to eliminate wrong answers

Option A is wrong because adding a Dockerfile to the source code and specifying it in the buildspec is used for building a new Docker image, not for running the build in an existing custom image from ECR. Option C is wrong because managed images provided by AWS CodeBuild are pre-configured environments (e.g., Ubuntu, Windows) and do not include custom dependencies that the company needs. Option D is wrong because passing the image URI as an environment variable does not instruct CodeBuild to use that image as the runtime environment; the image must be specified in the environment configuration's 'Image' field.

79
MCQmedium

A company is using AWS CodeDeploy to deploy a web application to an Auto Scaling group of EC2 instances. The deployment fails with the error 'The overall deployment failed because too many individual instances failed deployment.' What is the most likely cause?

A.The application specification file (appspec) is missing required hooks.
B.The IAM role for CodeDeploy does not have sufficient permissions to call EC2 APIs.
C.The Auto Scaling group does not have enough instances to meet the minimum healthy count.
D.The number of instances that failed deployment exceeded the configured failure threshold.
AnswerD

CodeDeploy allows you to define a deployment configuration that specifies the maximum number or percentage of instances that can fail during a deployment before the entire deployment is halted. When individual instances within a deployment group encounter issues during any lifecycle event (e.g., script execution failures, application startup errors, or health check failures), their deployment status is marked as failed. If the cumulative count of these failed instances surpasses the predefined failure threshold set in the deployment configuration, CodeDeploy will automatically stop the deployment and mark its overall status as failed, indicating that too many targets could not successfully complete the update.

Why this answer

The error message explicitly states that too many individual instances failed deployment, which means the number of failed instances exceeded the configured failure threshold (either the default or a custom value in the deployment configuration). CodeDeploy stops the deployment when this threshold is breached to prevent a full outage. The most likely cause is that the failure count crossed that limit, often due to a bad revision or environment issue.

Exam trap

DVA-C02 often tests whether candidates focus on the root cause of individual failures instead of recognizing that the error message describes the aggregate failure threshold being exceeded, leading them to pick appspec or IAM options.

How to eliminate wrong answers

Option A is wrong because a missing appspec hook would cause individual instance failures, but the error is specifically about the aggregate failure threshold being exceeded, not the root cause of each failure. Option B is wrong because insufficient IAM permissions would typically cause a different error (e.g., access denied) and would affect all instances uniformly, not trigger the 'too many individual instances failed' message. Option C is wrong because the minimum healthy count affects deployment success but the error message is about failed instances exceeding a threshold, not about insufficient instances.

80
MCQhard

A developer is creating a CloudFormation template to deploy a microservices architecture. The template includes an Amazon ECS service with an Application Load Balancer. The developer wants to ensure that the load balancer is created before the ECS service. How should the developer achieve this?

A.Use the Ref function in the ECS service to reference the load balancer.
B.Use the DependsOn attribute in the ECS service resource to reference the load balancer.
C.Define the load balancer before the ECS service in the template.
D.Use the Fn::GetAtt function to reference the load balancer.
AnswerB

The DependsOn attribute explicitly defines a creation, update, and deletion dependency between resources. By adding DependsOn: MyLoadBalancer to the ECS service resource, CloudFormation is instructed to ensure that MyLoadBalancer is completely provisioned and stable before it attempts to create or update the ECS service. This guarantees the load balancer is ready to accept registrations from ECS tasks, preventing deployment failures due to timing issues.

Why this answer

The DependsOn attribute explicitly defines resource creation order in AWS CloudFormation. By setting DependsOn on the ECS service to reference the load balancer, the template ensures the load balancer is fully created before the ECS service attempts to register with it, preventing deployment failures due to missing dependencies.

Exam trap

The trap here is that candidates assume the order of resource definitions in the template dictates creation order, but CloudFormation only guarantees order through explicit DependsOn or implicit dependencies from intrinsic functions like Ref or Fn::GetAtt used in resource properties.

How to eliminate wrong answers

Option A is wrong because the Ref function only returns a value (e.g., the load balancer's ARN or name) but does not enforce creation order; CloudFormation may still attempt to create the ECS service before the load balancer if there is no explicit dependency. Option C is wrong because the order of resource definitions in a CloudFormation template does not guarantee creation order; CloudFormation determines resource creation order based on intrinsic dependencies, not the sequence in the template file. Option D is wrong because Fn::GetAtt, like Ref, retrieves attribute values but does not create a dependency that ensures the load balancer is created before the ECS service; it only establishes a dependency if the attribute is used in a property that requires the resource to exist.

81
Multi-Selectmedium

A developer is deploying a web application using AWS Elastic Beanstalk. Which TWO configuration files can be used to customize the software that runs on the EC2 instances? (Select TWO.)

Select 2 answers
A..platform/hooks/
B.Dockerfile
C..ebextensions/*.config
D.appspec.yml
E.buildspec.yml
AnswersA, C

Elastic Beanstalk utilizes the `.platform/hooks/` directory to execute custom scripts at specific points during the application deployment lifecycle. These hooks, categorized as pre-init, pre-build, pre-deploy, and post-deploy, enable developers to perform tasks like installing dependencies, running database migrations, or modifying server configurations. This provides fine-grained control over the environment's setup and application startup process.

Why this answer

The `.platform/hooks/` directory is a feature of Elastic Beanstalk's platform-specific configuration that allows you to run custom scripts at specific lifecycle events (e.g., prebuild, postdeploy) on the EC2 instances. This is the modern replacement for the older `.ebextensions` approach for running commands during deployment, and it directly customizes the software running on the instances.

Exam trap

The trap here is that candidates often confuse Elastic Beanstalk configuration files with other AWS services' configuration files (like CodeDeploy's appspec.yml or CodeBuild's buildspec.yml) or assume a Dockerfile is universally applicable, when in fact only `.platform/hooks/` and `.ebextensions/*.config` are the two valid options for customizing software on EC2 instances in Elastic Beanstalk.

82
MCQmedium

A developer is using AWS Elastic Beanstalk to deploy a web application. The application uses an Amazon RDS database instance that is included in the Elastic Beanstalk environment. The developer wants to update the application code without affecting the database. What is the recommended approach?

A.Update the application code directly on the EC2 instances without redeploying the environment.
B.Create a new environment configuration, update the code, and swap the CNAME of the environments.
C.Decouple the database from the Elastic Beanstalk environment by creating a separate RDS instance and connecting the application to it externally.
D.Use Elastic Beanstalk's platform updates while keeping the database attached to the environment.
AnswerC

Decoupling the database by provisioning a standalone Amazon RDS instance outside the Elastic Beanstalk environment ensures its independent lifecycle management, allowing for separate scaling, backups, and patching. The application then connects to this external database using environment properties, guaranteeing data persistence and availability even if the Elastic Beanstalk environment is rebuilt, terminated, or updated, which is critical for production workloads.

Why this answer

When an RDS instance is included in an Elastic Beanstalk environment, it is tied to the environment's lifecycle. If the environment is terminated or rebuilt, the database is also deleted. Decoupling the database by creating a standalone RDS instance and connecting the application to it externally ensures the database persists independently of application deployments, allowing code updates without risking data loss.

Exam trap

The trap here is that candidates assume swapping CNAMEs between environments (blue/green deployment) is sufficient to protect the database, but they overlook that the database is still lifecycle-managed within each environment and will be lost if the original environment is terminated.

How to eliminate wrong answers

Option A is wrong because directly updating code on EC2 instances bypasses Elastic Beanstalk's managed deployment process, leading to configuration drift and loss of rollback capability. Option B is wrong because swapping CNAMEs between environments does not decouple the database; the new environment would still have its own lifecycle-managed RDS instance, and the original database remains tied to the old environment. Option D is wrong because platform updates only update the Elastic Beanstalk platform version, not the application code, and the database remains lifecycle-coupled, so any environment rebuild or termination would still affect the database.

83
MCQeasy

A company is using AWS CloudFormation to deploy a stack that includes an Amazon EC2 instance with an attached Amazon EBS volume. The developer wants to ensure that the EBS volume is deleted when the EC2 instance is terminated. The developer has set the DeletionPolicy attribute on the EBS volume resource to Delete. However, after terminating the EC2 instance through the console, the EBS volume is still present. The stack still exists. What is the most likely reason the volume was not deleted?

A.The EBS volume has a DeleteOnTermination attribute set to false.
B.The DeletionPolicy attribute only takes effect when the CloudFormation stack is deleted, not when an individual resource is terminated.
C.The EBS volume is the root device of the EC2 instance.
D.The EC2 instance was terminated manually, not through a stack update.
AnswerB

The DeletionPolicy attribute in AWS CloudFormation is specifically designed to control the fate of resources when their containing CloudFormation stack is deleted. It dictates whether a resource should be retained, snapshotted, or deleted during a DELETE stack operation. Therefore, if an individual EC2 instance is terminated, either manually or through an update that replaces the instance, the DeletionPolicy defined on its associated EBS volume resource within the CloudFormation template will not be evaluated or applied.

Why this answer

The DeletionPolicy attribute in CloudFormation governs what happens to a resource when it is removed from the stack template or when the stack itself is deleted — not when the underlying resource (the EC2 instance) is terminated by other means. Terminating the EC2 instance through the console does not trigger CloudFormation to evaluate the DeletionPolicy on the EBS volume, so the volume persists. To have the volume deleted on instance termination, the volume must have DeleteOnTermination=true on the block device mapping, which is an EC2-level attribute, not a CloudFormation DeletionPolicy concern.

Exam trap

DVA-C02 often tests the misconception that CloudFormation DeletionPolicy controls resource deletion during any lifecycle event, when in fact it only applies to stack deletion or resource removal from the template.

How to eliminate wrong answers

Option A is wrong because although DeleteOnTermination=false would indeed prevent deletion on instance termination, the question states the developer set DeletionPolicy=Delete, and the scenario is about CloudFormation behavior — the more likely reason is that DeletionPolicy simply doesn't apply to instance termination; also, the question doesn't state DeleteOnTermination is false. Option C is wrong because whether the volume is the root device is irrelevant to DeletionPolicy behavior; root volumes have their own DeleteOnTermination default (true) but that's not the cause here. Option D is wrong because terminating the instance manually versus through a stack update makes no difference — DeletionPolicy is only evaluated on stack deletion or resource removal from the template, not on instance termination regardless of how it's initiated.

84
Multi-Selecthard

A company uses AWS CodePipeline to automate deployments of a microservices application to Amazon ECS with Fargate. The pipeline has a deploy stage that uses Amazon ECS Blue/Green deployment. The deployment fails intermittently with a 'Task failed to start' error. The developer needs to troubleshoot the issue. Which THREE steps should the developer take? (Choose three.)

Select 3 answers
A.Review the CodeBuild build logs for errors.
B.Check the Amazon ECS service events for the task failure reason.
C.Validate that the task definition JSON is correctly formatted and references the correct container images.
D.Check the CloudFormation stack events for the ECS service.
E.Verify that the task execution IAM role has permissions to pull the container image from ECR.
AnswersB, C, E

The Amazon ECS service events tab is the authoritative source for recent service-level warnings and alarms, including deployment failures and stopped tasks. Each event often contains the exact error such as "CannotPullContainerError: Access Denied" or "task failed to start" along with a timestamp and the task ID. This is the first place an engineer should look because it directly records the reason ECS could not run the task.

Why this answer

Option B is correct because Amazon ECS service events provide the most direct diagnostic messages for tasks that fail to start, including reasons such as image pull failures, resource constraints, or unhealthy load balancer targets. Option C is correct because a malformed task definition JSON or an incorrect container image reference will prevent ECS from launching the task, producing exactly the 'Task failed to start' symptom. Option E is correct because the task execution IAM role must have permissions such as ecr:GetAuthorizationToken and ecr:BatchGetImage to pull the image from ECR; missing permissions cause task startup failures.

Option A is not appropriate because CodeBuild logs relate to the build stage, not the ECS deploy stage where the task fails to start. Option D is not appropriate because the pipeline uses Amazon ECS Blue/Green deployment, not a CloudFormation stack, so CloudFormation stack events would not explain the ECS task failure.

Exam trap

The trap is chasing the build stage (CodeBuild logs) or stack-level tooling (CloudFormation events) when the failure is at ECS task startup — candidates must recognize that ECS service events and the execution role are the authoritative sources for 'task failed to start'.

85
MCQhard

A developer is trying to update a CloudFormation stack that includes a Lambda function. The stack rolls back with the error shown. What is the most likely cause?

A.The Lambda function's execution role lacks permissions to write logs to CloudWatch.
B.The Lambda function's deployment package is not stored in Amazon S3.
C.The Lambda function's code is too large for the deployment.
D.The Lambda function's execution role does not have a trust policy that allows Lambda to assume it.
AnswerD

The execution role for an AWS Lambda function requires a trust policy that explicitly permits the `lambda.amazonaws.com` service principal to perform the `sts:AssumeRole` action. Without this crucial trust relationship, the Lambda service is unable to assume the specified role, preventing the successful creation or update of the function and resulting in an `AccessDeniedException` during the CloudFormation deployment.

Why this answer

The error message indicates that the IAM role cannot be assumed by Lambda. This typically means the trust policy of the execution role does not include 'lambda.amazonaws.com' as a trusted entity. Option A is incorrect because the error is about assuming the role, not about writing logs.

Option B is incorrect because the error is not about the deployment package location. Option C is incorrect because the error is not about code size.

86
MCQmedium

A company uses AWS OpsWorks to manage a stack of EC2 instances. After a deployment, the application becomes unresponsive. The engineer suspects that a configuration file was not updated correctly. What is the best way to verify the deployed configuration?

A.Use AWS Systems Manager Run Command to execute a script that outputs the configuration.
B.Check the OpsWorks stack's logs for any JSON syntax errors in the custom JSON.
C.SSH into an instance and inspect the configuration files in /var/lib/aws/opsworks.
D.Review the application logs in Amazon CloudWatch Logs for configuration errors.
AnswerC

When OpsWorks manages an EC2 instance, it uses Chef to apply configuration. The `/var/lib/aws/opsworks` directory on the instance is the authoritative location where Chef recipes, generated configuration files, and custom JSON are stored and executed. Directly inspecting these files allows a developer to verify the exact configuration that was actually deployed and applied to the instance, which is crucial for diagnosing why an application might be unresponsive due to misconfiguration.

Why this answer

OpsWorks stores its configuration data, including the applied custom JSON and stack settings, in /var/lib/aws/opsworks on each EC2 instance. By SSHing into the instance and inspecting these files, the engineer can directly verify whether the configuration file was updated correctly after deployment, bypassing any application-level logging or abstraction.

Exam trap

The trap here is that candidates assume CloudWatch Logs or Systems Manager Run Command are the best tools for configuration verification, overlooking the fact that OpsWorks stores its deployed configuration locally on the instance in a specific directory that can only be inspected directly via SSH.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Run Command can execute scripts, but it does not provide direct access to the OpsWorks-specific configuration files stored on the instance; it would require the script to read those files, which is less direct than SSH inspection. Option B is wrong because OpsWorks stack logs may show JSON syntax errors in custom JSON, but they do not reveal whether the configuration file was correctly applied to the instance after deployment; syntax errors are only one possible cause. Option D is wrong because application logs in CloudWatch Logs may indicate configuration errors, but they are an indirect indicator and may not reflect the exact state of the configuration file on disk, especially if the application fails before logging.

87
MCQeasy

A developer is using AWS CodeDeploy to deploy an application to an Auto Scaling group. The deployment is configured with a 'OneAtATime' deployment configuration. The developer notices that the deployment is taking a long time. What is the most likely reason?

A.The deployment group is configured with an incorrect load balancer.
B.The Auto Scaling group has a large number of instances, and deploying one at a time is slow.
C.The deployment configuration is set to 'AllAtOnce', but the developer intended 'OneAtATime'.
D.The CodeDeploy agent on the instances is not running.
AnswerB

The OneAtATime deployment configuration deliberately updates exactly one instance at a time, waiting for each instance's lifecycle event hooks (BeforeInstall, ApplicationStop, Install, AfterInstall, ApplicationStart, ValidateService) to complete successfully before moving to the next; with a large Auto Scaling group, this strictly sequential process multiplies the per-instance deployment time by the total instance count, making the overall deployment noticeably slow by design.

Why this answer

The 'OneAtATime' deployment configuration deploys to one instance at a time, so if the Auto Scaling group has a large number of instances, the deployment will take a long time. Option A is incorrect because the load balancer configuration does not directly affect deployment speed when using 'OneAtATime'. Option C is incorrect because the deployment configuration is correctly set to 'OneAtATime', not 'AllAtOnce'.

Option D is incorrect because if the CodeDeploy agent were not running, the deployment would likely fail entirely, not just be slow.

88
MCQeasy

A developer uses AWS CodePipeline with a manual approval step before deployment. The developer wants to ensure that if a new commit is pushed while a pipeline execution is waiting for approval, the waiting execution is canceled and a new one starts with the latest commit. Which pipeline execution mode should be configured?

A.Queued
B.Superseded
C.Parallel
D.Single
AnswerB

Superseded mode is designed to prioritize the most recent changes by immediately stopping any currently active pipeline execution, including those paused at a manual approval step. Upon cancellation of the in-progress execution, a brand new pipeline execution is initiated using the latest source code revisions. This ensures that developers can quickly iterate and deploy updates without waiting for older, potentially stalled, deployments to complete, making it ideal for continuous integration/continuous delivery (CI/CD) workflows where rapid feedback is crucial.

Why this answer

The Superseded execution mode is designed to automatically cancel any in-progress pipeline execution when a new commit is pushed, and start a new execution with the latest source changes. This ensures that the manual approval step does not block newer commits, as the waiting execution is replaced by the one triggered by the latest commit. In contrast, other modes either queue or run executions in parallel, which would not cancel the waiting approval step.

Exam trap

The trap here is that candidates may confuse Superseded with Queued, thinking that queuing will handle the latest commit, but Queued only delays execution without canceling the waiting approval step.

How to eliminate wrong answers

Option A is wrong because Queued mode places new executions in a queue, waiting for the current execution to complete before starting the next one, which would not cancel the waiting approval step. Option C is wrong because Parallel mode allows multiple executions to run concurrently, which would not cancel the waiting execution and could lead to multiple approvals or deployments. Option D is wrong because Single mode is not a valid execution mode in AWS CodePipeline; the valid modes are Queued, Superseded, and Parallel.

89
MCQhard

A development team wants to automate the deployment of a microservices application on Amazon ECS with Fargate. The team uses AWS CodePipeline for CI/CD. Each microservice has its own source repository and Dockerfile. The team wants to build Docker images, push them to Amazon ECR, and deploy them to ECS. Which approach minimizes manual effort and follows best practices?

A.Use AWS CodeDeploy to deploy to ECS with a blue/green deployment.
B.Use AWS CloudFormation to create the infrastructure and manually trigger updates.
C.Use AWS CodePipeline with a build stage in CodeBuild and a deploy stage that uses the ECS deploy provider.
D.Use AWS CodeBuild to build and push images, then manually update the ECS service.
AnswerC

CodePipeline can orchestrate source, a CodeBuild stage that builds the Docker image and pushes it to ECR (producing an imagedefinitions.json artifact), and a deploy stage using the built-in Amazon ECS deploy action provider, which updates the task definition and service automatically on every commit with no manual steps.

Why this answer

AWS CodePipeline provides a fully automated CI/CD pipeline. With the ECS deploy provider, CodePipeline can update the ECS service with the new task definition directly, eliminating manual steps. Option A is incorrect because adding CodeDeploy for blue/green deployments introduces unnecessary complexity for a basic ECS deployment; the ECS deploy provider in CodePipeline handles it without additional services.

Option B is incorrect because it requires manual triggering of CloudFormation updates, which does not achieve full automation. Option D is incorrect because it requires manual intervention to update the ECS service, contradicting the goal of minimizing manual effort.

90
MCQhard

A team wants CloudFormation to prevent accidental deletion of a production DynamoDB table during stack updates. What should they configure?

A.A larger write capacity setting
B.A Lambda layer
C.An API Gateway usage plan
D.DeletionPolicy or UpdateReplacePolicy Retain as appropriate
AnswerD

CloudFormation provides the `DeletionPolicy` and `UpdateReplacePolicy` attributes specifically to control the lifecycle of resources during stack operations. Setting `DeletionPolicy` to `Retain` ensures that a resource is not deleted when its containing stack is deleted or the resource is removed from the template. Similarly, `UpdateReplacePolicy` set to `Retain` prevents the old physical resource from being deleted if it is replaced during a stack update, directly addressing the requirement to prevent accidental resource deletion.

Why this answer

The DeletionPolicy attribute with a value of Retain instructs AWS CloudFormation to preserve the DynamoDB table when its stack resource is deleted during a stack update or stack deletion. Similarly, UpdateReplacePolicy Retain ensures that if a resource replacement is required during an update, the existing table is kept rather than deleted. This directly prevents accidental data loss by overriding CloudFormation's default behavior of deleting resources that are removed from the template or replaced.

Exam trap

The trap here is that candidates may confuse operational settings (like write capacity) or unrelated services (Lambda layers, API Gateway) with CloudFormation's resource lifecycle policies, missing the direct purpose of DeletionPolicy and UpdateReplacePolicy.

How to eliminate wrong answers

Option A is wrong because a larger write capacity setting only affects DynamoDB's throughput performance and has no impact on resource lifecycle or deletion prevention. Option B is wrong because a Lambda layer is used to package runtime dependencies for Lambda functions and does not influence CloudFormation's resource deletion behavior. Option C is wrong because an API Gateway usage plan throttles and monitors API requests for billing or rate-limiting purposes and is unrelated to CloudFormation stack resource protection.

91
MCQeasy

A developer is deploying a serverless application using the AWS Serverless Application Model (SAM). The developer runs 'sam deploy' and receives an error: 'Error: Failed to create changeset for the stack.' What is a common cause of this error?

A.The SAM template contains a syntax error.
B.The S3 bucket specified for artifacts does not exist.
C.The IAM user does not have permission to create CloudFormation stacks.
D.AWS CodeDeploy is not configured for the application.
AnswerA

When `sam deploy` (or `aws cloudformation deploy`) is executed, the CloudFormation service first validates the template's syntax and structure. If the SAM template, which is an extension of CloudFormation, contains a syntax error (e.g., incorrect YAML/JSON formatting, invalid intrinsic function usage, or malformed resource properties), CloudFormation will fail to parse it. This failure occurs early in the deployment process, specifically preventing the successful creation of a changeset, as the service cannot understand the desired state described by the invalid template.

Why this answer

The 'Failed to create changeset for the stack' error typically occurs when the SAM template contains a syntax error, such as invalid YAML formatting, missing required properties, or incorrect resource definitions. AWS CloudFormation validates the template before creating a changeset, and any syntax issue will cause the changeset creation to fail immediately. This is the most common cause because SAM templates are YAML-based and prone to indentation or structural mistakes.

Exam trap

The trap here is that candidates often confuse changeset creation failures with permission or bucket issues, but the error message specifically points to template validation, not infrastructure or IAM problems.

How to eliminate wrong answers

Option B is wrong because if the S3 bucket specified for artifacts does not exist, the error would be 'Unable to upload artifact...' or 'Bucket not found', not a changeset creation failure. Option C is wrong because insufficient IAM permissions to create CloudFormation stacks would result in an 'AccessDenied' or authorization error, not a changeset creation failure. Option D is wrong because AWS CodeDeploy is not required for SAM deployments; SAM uses CloudFormation for infrastructure provisioning, and CodeDeploy is only relevant if you configure a separate deployment pipeline.

92
MCQeasy

A developer is using AWS CloudFormation to create a stack that includes an EC2 instance. The stack creation fails because the instance type is not supported in the selected Availability Zone. What should the developer do?

A.Delete the stack and start over.
B.Change the instance type to one that is supported.
C.Update the stack to specify a different subnet or not specify an Availability Zone.
D.Create the stack in a different region.
AnswerC

Updating the stack to specify a different subnet or removing the explicit Availability Zone (AZ) specification is the most effective and flexible solution. If a specific AZ lacks capacity for the requested instance type, deploying into a different subnet, which is tied to another AZ, can resolve the issue. Alternatively, by not specifying an AZ, CloudFormation can automatically select an available AZ with sufficient capacity for the desired instance type, ensuring successful deployment while maintaining the intended resource configuration. This leverages CloudFormation's intelligence to handle underlying infrastructure constraints.

Why this answer

When an EC2 instance type is not supported in a specific Availability Zone (AZ), the developer can update the CloudFormation stack to either specify a different subnet (which implicitly selects a different AZ) or omit the Availability Zone parameter entirely, allowing AWS to automatically choose an AZ where the instance type is supported. This avoids the need to delete the stack or change the instance type, preserving other stack resources and configurations.

Exam trap

The trap here is that candidates assume the only fix is to change the instance type (Option B) or restart from scratch (Option A), overlooking CloudFormation's ability to update the stack's subnet or AZ selection to match the instance type's availability.

How to eliminate wrong answers

Option A is wrong because deleting the stack and starting over is unnecessary and inefficient; the issue can be resolved by updating the stack's subnet or AZ specification without losing existing resources. Option B is wrong because changing the instance type may not be desirable if the developer specifically needs that instance type for performance or cost reasons; the problem is the AZ constraint, not the instance type itself. Option D is wrong because creating the stack in a different region is an overreaction; the instance type is likely supported in other AZs within the same region, and changing regions could introduce latency, cost, or compliance issues.

93
MCQmedium

A developer is using AWS CodeDeploy to deploy a new version of an AWS Lambda function. The developer wants to gradually shift traffic from the old version to the new version in 10-minute increments. Which deployment configuration should the developer use?

A.Canary10Percent10Minutes
B.Canary10Percent30Minutes
C.Linear10PercentEvery10Minutes
D.AllAtOnce
AnswerC

This CodeDeploy configuration precisely aligns with the requirement for gradual, incremental traffic shifts. It systematically routes 10% of traffic to the new Lambda version, waits for 10 minutes, then shifts another 10%, repeating this process until 100% of traffic is successfully moved. This ensures a controlled, step-by-step rollout, allowing for continuous monitoring and potential rollback at each 10-minute interval.

Why this answer

The Linear10PercentEvery10Minutes configuration shifts traffic from the old Lambda version to the new version in 10% increments every 10 minutes, which matches the developer's requirement of gradually shifting traffic in 10-minute increments. This is a linear deployment type in AWS CodeDeploy that provides a steady, incremental traffic shift over time.

Exam trap

The trap here is confusing canary deployments (which shift a small percentage immediately and then the remainder after a wait) with linear deployments (which shift traffic in equal increments over time), leading candidates to select a canary configuration when a linear one is required.

How to eliminate wrong answers

Option A is wrong because Canary10Percent10Minutes shifts 10% of traffic to the new version immediately, then waits 10 minutes before shifting the remaining 90% all at once, which does not provide gradual 10-minute increments. Option B is wrong because Canary10Percent30Minutes shifts 10% immediately, then waits 30 minutes before shifting the remaining 90%, which does not match the 10-minute increment requirement. Option D is wrong because AllAtOnce shifts 100% of traffic to the new version immediately with no gradual traffic shifting, which contradicts the developer's requirement.

94
MCQmedium

A developer is deploying a new version of an AWS Lambda function using the AWS CLI. The developer wants to create a new version and update the alias to point to the new version. Which sequence of CLI commands should the developer use?

A.Update alias, update function code, publish version
B.Create alias, update function code, publish version
C.Publish version, update function code, update alias
D.Update function code, publish version, update alias
AnswerD

First, updating the function code ensures the `$LATEST` version contains the desired new logic. Next, publishing a version creates an immutable snapshot of this updated code, providing a stable reference point. Finally, updating the alias to point to this newly published version allows for controlled traffic shifting, enabling safe deployments, rollbacks, and advanced strategies like canary releases.

Why this answer

The correct sequence is to first update the function code, then publish a new version, and finally update the alias to point to that new version. The `update-function-code` command uploads the new code to the $LATEST version, `publish-version` creates an immutable numbered version from $LATEST, and `update-alias` updates the alias to reference that specific version. This ensures the alias always points to a stable, published version rather than the mutable $LATEST.

Exam trap

The trap here is that candidates often think they can update the alias before publishing the version, or they confuse the order of operations by assuming the alias can point to $LATEST, but the exam requires the alias to reference a specific published version for immutability and rollback safety.

How to eliminate wrong answers

Option A is wrong because it attempts to update the alias before the new version exists, which would fail or point to a non-existent version. Option B is wrong because it creates a new alias instead of updating an existing one, and also attempts to update the alias before the version is published. Option C is wrong because it publishes a version before updating the function code, which would publish the old code, and then updates the function code to $LATEST without publishing a new version, leaving the alias pointing to the old published version.

95
MCQeasy

A developer is deploying an application using AWS Elastic Beanstalk. The application needs to connect to an Amazon RDS database. What is the best practice for storing database credentials?

A.Hardcode the credentials in the application code.
B.Store credentials in Elastic Beanstalk environment properties.
C.Store credentials in an Amazon S3 bucket with public read access.
D.Store credentials in AWS Secrets Manager and retrieve them at runtime.
AnswerD

AWS Secrets Manager is the recommended and most secure service for storing and managing sensitive credentials. It encrypts secrets at rest and in transit, allows for automatic rotation of credentials, and provides fine-grained access control through AWS IAM policies, ensuring only authorized applications or services can retrieve them at runtime. This approach minimizes the exposure window and enhances the overall security posture by centralizing secret management.

Why this answer

AWS Secrets Manager provides a secure, auditable service for rotating and managing database credentials. By retrieving secrets at runtime via the AWS SDK, the application avoids embedding sensitive data in code or configuration, which is a key security best practice for Elastic Beanstalk deployments.

Exam trap

The trap here is that candidates often confuse Elastic Beanstalk environment properties with secure storage, not realizing they are stored in plaintext and accessible via the environment configuration, unlike Secrets Manager which provides encryption and rotation.

How to eliminate wrong answers

Option A is wrong because hardcoding credentials in application code exposes them in version control and static analysis, violating the principle of least privilege and making rotation impossible without redeployment. Option B is wrong because Elastic Beanstalk environment properties are stored in plaintext in the environment configuration and can be viewed by anyone with access to the Elastic Beanstalk console or API, offering no encryption at rest or rotation capabilities. Option C is wrong because storing credentials in an S3 bucket with public read access exposes them to the entire internet, directly violating AWS security best practices and potentially leading to data breaches.

96
MCQmedium

A developer is using AWS Elastic Beanstalk to deploy a web application. The application requires a highly available environment across multiple Availability Zones. The developer wants to update the application without any downtime while minimizing the number of new instances launched. Which deployment policy should the developer use?

A.All at once
B.Rolling
C.Rolling with additional batch
D.Immutable
AnswerC

Rolling with additional batch maintains full capacity by launching a new batch before terminating old instances, keeping the environment highly available across Availability Zones. It updates without downtime while launching fewer extra instances than immutable or blue/green.

Why this answer

(Rolling with additional batch) is correct because it launches a new batch of instances before taking the old ones out of service, ensuring full capacity is maintained during the deployment. This provides high availability across multiple Availability Zones while minimizing the number of new instances compared to an immutable deployment, which would double the instance count. The additional batch absorbs the traffic during the rolling update, preventing any downtime.

Exam trap

The trap here is that candidates confuse 'Rolling' with 'Rolling with additional batch', assuming both provide zero downtime, but only the latter guarantees full capacity throughout the update by adding an extra batch to absorb traffic.

How to eliminate wrong answers

Option A is wrong because 'All at once' deploys the new version to all instances simultaneously, causing downtime as all instances are replaced at the same time. Option B is wrong because 'Rolling' updates instances in batches without an extra batch, which reduces capacity during the update and can lead to downtime if the application cannot handle reduced load. Option D is wrong because 'Immutable' launches a completely new set of instances in a new Auto Scaling group, then swaps the environment, which minimizes downtime but launches the maximum number of new instances (doubling the count), contradicting the requirement to minimize new instances.

97
MCQhard

A company uses AWS CodeCommit for source control. A developer needs to automate the build and test process for every commit to the 'develop' branch. The developer creates a CodeBuild project and wants to trigger it automatically. What is the most efficient way to set up this automation?

A.Create a CloudWatch Events rule that triggers CodeBuild on code commit events
B.Configure a webhook in CodeCommit to call CodeBuild directly
C.Create a CodePipeline with a source stage from CodeCommit and a build stage from CodeBuild
D.Use an SQS queue to receive SNS notifications from CodeCommit and trigger CodeBuild
AnswerC

Creating an AWS CodePipeline with CodeCommit as the source stage and CodeBuild as the build stage is the most appropriate and recommended solution. CodePipeline is purpose-built for continuous integration and continuous delivery (CI/CD) workflows, offering seamless, native integration between these services. It automatically detects changes in the CodeCommit repository, orchestrates the build process in CodeBuild, and manages artifact passing between stages, providing a fully automated and efficient pipeline.

Why this answer

AWS CodePipeline is the most efficient and fully managed way to orchestrate a continuous integration workflow. It natively integrates CodeCommit as a source action that automatically detects changes on the specified branch (e.g., 'develop') and triggers a CodeBuild build stage without any custom scripting or additional infrastructure. This provides built-in retry, status tracking, and seamless integration with other AWS services.

Exam trap

The trap here is that candidates may overcomplicate the solution by considering event-driven services like CloudWatch Events or SQS, when the simplest and most efficient approach is to use CodePipeline's native source-to-build integration, which is purpose-built for this exact scenario.

How to eliminate wrong answers

Option A is wrong because CloudWatch Events (now Amazon EventBridge) can trigger CodeBuild on CodeCommit events, but this requires creating a custom event rule and does not provide the native pipeline orchestration, artifact handling, or stage sequencing that CodePipeline offers; it is less efficient and more manual to maintain. Option B is wrong because CodeCommit does not support configuring webhooks to directly call CodeBuild; webhooks are typically used with third-party Git providers (e.g., GitHub, Bitbucket) and CodeCommit uses repository triggers that can invoke AWS Lambda or SNS, not directly call CodeBuild. Option D is wrong because using an SQS queue to receive SNS notifications from CodeCommit and then triggering CodeBuild adds unnecessary complexity and latency; it requires setting up SNS, SQS, and a custom polling mechanism, which is far less efficient than the native integration provided by CodePipeline.

98
MCQmedium

A developer is using AWS SAM to define a serverless application. The application includes an AWS Lambda function and an Amazon API Gateway REST API. The developer wants to configure the API Gateway stage to enable logging and set the stage name based on the SAM parameter Stage. In the SAM template, which property of the AWS::Serverless::Api resource should the developer use to set the stage name?

A.StageName
B.DefinitionBody
C.StageDescription
D.EndpointConfiguration
AnswerA

The StageName property within an AWS::Serverless::Api resource in AWS SAM is precisely what defines the name of the Amazon API Gateway deployment stage. This critical property allows developers to specify a logical identifier for a particular deployment, such as Prod, Dev, or Test, which is essential for managing different environments. It frequently leverages SAM parameters, like !Ref Stage, enabling dynamic stage naming based on deployment inputs, ensuring flexibility and reusability across various CI/CD pipelines.

Why this answer

The `StageName` property of the `AWS::Serverless::Api` resource directly sets the stage name for the API Gateway REST API. By using a SAM parameter like `Stage` (e.g., `StageName: !Ref Stage`), the developer can dynamically control the stage name at deployment time. This is the intended and simplest way to configure the stage name in an AWS SAM template.

Exam trap

The trap here is that candidates confuse `StageName` with `StageDescription` (Option C) because both relate to stage configuration, but `StageDescription` only provides metadata and does not control the actual stage identifier used in the API endpoint URL.

How to eliminate wrong answers

Option B (`DefinitionBody`) is wrong because it defines the OpenAPI specification for the API, not the stage name; it can include a `stageName` field within the OpenAPI definition, but that is not the SAM-level property for setting the stage name. Option C (`StageDescription`) is wrong because it provides a description of the stage (e.g., for documentation or tagging), not the stage name itself. Option D (`EndpointConfiguration`) is wrong because it specifies the endpoint type (e.g., REGIONAL, EDGE, PRIVATE) for the API, not the stage name.

99
MCQhard

An ECS blue/green deployment with CodeDeploy and an Application Load Balancer fails because the replacement task set never receives test traffic. Which configuration should be checked?

A.S3 bucket versioning
B.Lambda provisioned concurrency
C.The test listener and target group mapping in the deployment group
D.DynamoDB TTL
AnswerC

In an AWS CodeDeploy Blue/Green deployment for Amazon ECS, the test listener and its mapping to a new target group are fundamental for validating the new task set (the 'green' environment). CodeDeploy uses this listener to route a small amount of traffic, or traffic from a specific test client, to the new target group associated with the updated application tasks. This crucial step allows for pre-validation and ensures the new application version is healthy and functional before the final production traffic cutover, enabling safe rollouts and easy rollbacks.

Why this answer

In an ECS blue/green deployment with CodeDeploy and an Application Load Balancer, the test listener and its associated target group are responsible for routing test traffic to the replacement task set. If the replacement task set never receives test traffic, the most likely cause is that the test listener is not correctly mapped to the target group in the CodeDeploy deployment group configuration. This mapping ensures that traffic from the test listener is directed to the replacement task set during the deployment lifecycle.

Exam trap

The trap here is that candidates may confuse the test listener with the production listener or assume the issue is with the ALB itself, rather than recognizing that the test listener-to-target-group mapping in the CodeDeploy deployment group is the specific configuration that controls test traffic routing.

How to eliminate wrong answers

Option A is wrong because S3 bucket versioning is unrelated to ECS deployment traffic routing; it is used for object version control and rollback in S3, not for CodeDeploy traffic routing. Option B is wrong because Lambda provisioned concurrency is a feature for managing concurrent execution capacity of Lambda functions, not for ECS task set traffic routing in blue/green deployments. Option D is wrong because DynamoDB TTL (Time to Live) is a feature for automatically expiring items in DynamoDB tables, and it has no role in CodeDeploy or ALB traffic routing.

100
Multi-Selectmedium

A company uses AWS Elastic Beanstalk to deploy a web application. The application uses an Amazon RDS database. The developer wants to ensure that the database connection string is not hard-coded in the application code. Which THREE methods can the developer use to pass the connection string securely? (Choose THREE.)

Select 3 answers
A.Read the connection string from Amazon RDS tags.
B.Use AWS Secrets Manager.
C.Use Elastic Beanstalk environment properties.
D.Store the connection string in a configuration file in the application bundle.
E.Use AWS Systems Manager Parameter Store.
AnswersB, C, E

AWS Secrets Manager is purpose-built for this task: it stores the connection string as a secret encrypted by a KMS key, provides fine-grained access control through IAM policies, and natively supports automatic rotation for Amazon RDS credentials. The application can retrieve the secret at runtime using the AWS SDK, and you can even integrate it with Elastic Beanstalk via a custom resource or startup script. This minimizes human exposure and lets you change credentials without rebuilding or redeploying the application.

Why this answer

Option B is correct because AWS Secrets Manager is purpose-built to store and retrieve secrets such as database connection strings, supporting encryption at rest with KMS and fine-grained access via IAM, so the application can fetch the string at runtime instead of hard-coding it. Option C is correct because Elastic Beanstalk environment properties are injected into the application as environment variables (for example, RDS_HOSTNAME, RDS_USERNAME, RDS_PASSWORD that Beanstalk itself sets for attached RDS instances), letting the code read the connection string from the environment rather than embedding it. Option E is correct because AWS Systems Manager Parameter Store can hold the connection string as a SecureString parameter encrypted with KMS, and the application can retrieve it via the SSM API or the EC2/Beanstalk instance role.

Option A is not appropriate because RDS tags are metadata for resource organization, cost allocation, and access control, not a secure mechanism for delivering secrets to an application. Option D is not appropriate because a configuration file inside the application bundle is still effectively hard-coded and travels with the source artifact, so it does not securely externalize the connection string.

Exam trap

DVA-C02 often tests the difference between secure secret storage (Secrets Manager, Parameter Store) and insecure embedding (config files, tags) — the trap is picking a config file because it 'isn't in the code' even though it is still in the deployment bundle.

101
MCQhard

A company uses AWS CodeDeploy to deploy an application to EC2 instances. The deployment fails with the error: 'The overall deployment failed because too many individual instances failed deployment, too few healthy instances are available, or some instances in your deployment group are experiencing problems.' The deployment group consists of 4 EC2 instances. The deployment configuration is 'CodeDeployDefault.OneAtATime'. The CodeDeploy agent logs on the failed instance show: 'Error: Script at specified location: scripts/install_dependencies.sh failed with exit code 1.' What should the developer do to resolve this issue?

A.Change the deployment configuration to 'CodeDeployDefault.AllAtOnce'.
B.Review the install_dependencies.sh script for errors and correct them.
C.Reinstall the CodeDeploy agent on the failed instance.
D.Increase the number of EC2 instances in the deployment group.
AnswerB

The problem statement indicates that the install_dependencies.sh script failed, which is a critical step in the CodeDeploy application lifecycle hooks, typically executed during the BeforeInstall or Install phase. When this script fails, CodeDeploy marks the instance deployment as unsuccessful because the necessary dependencies or setup steps were not completed. Identifying and correcting syntax errors, missing commands, incorrect paths, or permission issues within this specific script will directly resolve the root cause of the deployment failures, allowing subsequent deployments to succeed.

Why this answer

The error message clearly indicates that the install_dependencies.sh script failed with exit code 1 on the instance. The root cause is a problem within the script itself (e.g., a failed package install, missing dependency, or syntax error). The developer must review and correct the script to resolve the deployment failure.

Exam trap

DVA-C02 often tests whether candidates focus on the actual error message (script exit code 1) versus superficial fixes like changing deployment configuration or reinstalling the agent — the trap is ignoring the script-level root cause.

How to eliminate wrong answers

Option A is wrong because changing to AllAtOnce would deploy to all instances simultaneously, potentially causing more failures, and does not fix the underlying script error. Option C is wrong because reinstalling the CodeDeploy agent would not fix a script that exits with code 1 — the agent is functioning correctly by reporting the failure. Option D is wrong because adding more instances does not address the script error and would likely result in more failed deployments.

102
MCQeasy

A developer wants to deploy a serverless application using AWS CloudFormation. The application consists of an API Gateway, Lambda functions, and DynamoDB tables. The developer wants to ensure that the stack can be updated without resource interruption when possible. Which CloudFormation feature should the developer use?

A.Use a Lambda alias with a DeploymentPreference update policy
B.Use a ChangeSet to review changes before applying them
C.Use a StackPolicy to protect critical resources
D.Use a Custom Resource to manage updates
AnswerA

CloudFormation's `AWS::Lambda::Alias` resource, when combined with a `DeploymentPreference` update policy, facilitates controlled, gradual traffic shifting between a Lambda function's current version and a newly deployed version. This strategy leverages AWS CodeDeploy to manage the rollout, allowing for canary deployments or linear shifts, which ensures that updates are applied without service interruption by routing traffic incrementally and automatically rolling back if issues are detected.

Why this answer

The `DeploymentPreference` update policy on a Lambda alias enables canary, linear, or all-at-once traffic shifting during stack updates. This allows the developer to update Lambda function versions without interrupting existing invocations, as traffic is gradually routed to the new version while the old version continues to serve requests until the transition completes.

Exam trap

The trap here is that candidates often confuse ChangeSets (which only preview changes) with the actual update mechanism, or they mistakenly think StackPolicies or Custom Resources can control update behavior, when in fact only the `DeploymentPreference` update policy on a Lambda alias provides the traffic-shifting capability needed for uninterrupted updates.

How to eliminate wrong answers

Option B is wrong because a ChangeSet only provides a preview of the changes that will be applied to the stack; it does not prevent resource interruption during the update itself. Option C is wrong because a StackPolicy is used to prevent accidental updates or deletions of specific resources by denying update/delete actions, but it does not control how updates are rolled out to avoid interruption. Option D is wrong because a Custom Resource is used to handle provisioning of resources not natively supported by CloudFormation, not to manage update strategies for Lambda functions.

103
Multi-Selecthard

Which THREE steps are required to set up a continuous delivery pipeline using AWS CodePipeline, CodeBuild, and CodeDeploy? (Select THREE.)

Select 3 answers
A.Set up an Amazon RDS database to store deployment logs.
B.Create a deploy stage with CodeDeploy to deploy the artifacts.
C.Configure an AWS Lambda function to trigger the pipeline.
D.Create a build stage with CodeBuild to compile and test the code.
E.Create a source stage that retrieves code from a repository.
AnswersB, D, E

A deploy stage is an absolutely essential component of any continuous delivery pipeline, responsible for taking the validated build artifacts and deploying them to the target environment. AWS CodeDeploy is the primary service used within CodePipeline for this purpose, supporting deployments to Amazon EC2 instances, AWS Lambda functions, and Amazon ECS services. This stage automates the release process, ensuring that the application is consistently and reliably delivered to production or staging environments after successful compilation and testing.

Why this answer

Option B is correct because a CodePipeline continuous delivery pipeline requires a deploy stage, and CodeDeploy is the AWS service used in that stage to deploy the built artifacts to targets such as EC2 instances, Lambda functions, or ECS services. Option D is correct because CodeBuild provides the build stage where the source code is compiled, tested, and packaged into deployable artifacts, which is a core step in a CodePipeline workflow. Option E is correct because every CodePipeline must begin with a source stage that retrieves the code from a repository such as AWS CodeCommit, GitHub, or Amazon S3, which then triggers the pipeline on changes.

Option A is incorrect because CodePipeline and CodeDeploy do not require an Amazon RDS database to store deployment logs; logs are handled by CloudWatch Logs and S3 artifacts. Option C is incorrect because CodePipeline is natively triggered by source changes or EventBridge rules, not by a custom Lambda function, so creating a Lambda trigger is not a required setup step.

Exam trap

The trap here is that candidates often think a database or a Lambda trigger is a required component, but the core pipeline only needs source, build, and deploy stages; additional services like RDS or Lambda are optional and not part of the minimal setup.

104
MCQmedium

A team is using AWS CodeBuild to compile and test code. The build takes longer than expected. The team wants to reduce build times by caching dependencies. Which option should the team use to cache dependencies in CodeBuild?

A.Amazon DynamoDB
B.Amazon EFS
C.Amazon ECR
D.Local caching or Amazon S3 caching
AnswerD

AWS CodeBuild natively supports both local caching and Amazon S3 caching to significantly speed up build times. Local caching stores a cache directory on the build host's file system, reusing dependencies across subsequent builds on the same host. Amazon S3 caching, a more scalable option, uploads and downloads a compressed cache archive to and from an S3 bucket, making the cache available across different build hosts and providing durability and shareability for build dependencies and artifacts.

Why this answer

AWS CodeBuild supports two caching modes: local caching and Amazon S3 caching. Local caching stores dependencies on the build host's local file system, while S3 caching stores them in an S3 bucket. Both options reduce build times by reusing previously downloaded dependencies across builds, avoiding redundant downloads.

Exam trap

The trap here is that candidates may confuse caching mechanisms with storage services like DynamoDB or EFS, or assume that ECR (used for container images) can cache dependencies, when CodeBuild specifically supports only local and S3 caching for dependency reuse.

How to eliminate wrong answers

Option A is wrong because Amazon DynamoDB is a NoSQL database service, not a caching mechanism for build dependencies; it is used for storing structured data, not for caching build artifacts or dependency files. Option B is wrong because Amazon EFS is a scalable file system for use with AWS services and on-premises resources, but it is not a caching option supported by CodeBuild for build dependencies; CodeBuild does not natively integrate with EFS for caching. Option C is wrong because Amazon ECR is a container image registry, used for storing and managing Docker images, not for caching build dependencies; it is unrelated to dependency caching in CodeBuild.

105
MCQmedium

A developer is deploying a serverless application using AWS SAM. The application includes an API Gateway endpoint backed by a Lambda function. The developer wants to enable canary deployments to shift 10% of traffic to the new version for 5 minutes before routing all traffic. Which configuration should the developer add to the SAM template?

A.DeploymentPreference with Type: Canary10Percent5Minutes
B.Add a CodeDeploy application and deployment group manually
C.DeploymentPreference with Type: Linear10PercentEvery1Minute
D.DeploymentPreference with Type: AllAtOnce
AnswerA

For serverless applications deployed with AWS SAM, `DeploymentPreference` integrates with AWS CodeDeploy to manage traffic shifting. A `Canary10Percent5Minutes` strategy first routes 10% of traffic to the new Lambda function version for 5 minutes. If no alarms are triggered during this period, CodeDeploy automatically shifts the remaining 90% of traffic to the new version, providing a controlled rollout and minimizing impact from potential issues. This phased approach is ideal for validating new deployments in a production environment.

Why this answer

The `DeploymentPreference` property with `Type: Canary10Percent5Minutes` instructs AWS SAM to use AWS CodeDeploy to shift 10% of traffic to the new Lambda version for 5 minutes, then automatically route the remaining 90% after the canary period ends. This matches the requirement exactly, leveraging SAM's built-in integration with CodeDeploy for canary deployments.

Exam trap

The trap here is that candidates confuse `Canary10Percent5Minutes` with `Linear10PercentEvery1Minute`, thinking both are canary deployments, but only the former holds traffic at 10% for a fixed duration before shifting all at once, while the latter shifts incrementally every minute.

How to eliminate wrong answers

Option B is wrong because manually adding a CodeDeploy application and deployment group is unnecessary and error-prone; AWS SAM automatically creates and manages the CodeDeploy resources when you specify `DeploymentPreference` in the template. Option C is wrong because `Linear10PercentEvery1Minute` shifts traffic in 10% increments every minute, which does not match the requirement of a single 10% shift for 5 minutes before routing all traffic. Option D is wrong because `AllAtOnce` routes 100% of traffic to the new version immediately, bypassing any canary or gradual deployment strategy.

106
Multi-Selecteasy

Which TWO strategies can be used to reduce the risk of a failed deployment when using AWS CodeDeploy? (Select TWO.)

Select 2 answers
A.Configure automatic rollback based on CloudWatch alarms.
B.Use a canary deployment to shift traffic gradually.
C.Disable health checks to prevent false positives.
D.Require a manual approval step before deployment.
E.Deploy to all instances at once to ensure consistency.
AnswersA, B

When a deployment causes performance degradation or errors, CloudWatch alarms can detect these issues by monitoring key metrics such as error rates, latency, or CPU utilization. Configuring automatic rollback to trigger upon these alarm states ensures that the application quickly reverts to a stable previous version, minimizing the blast radius and user impact of a faulty deployment. This proactive measure significantly reduces the duration of service disruption and enhances reliability.

Why this answer

AWS CodeDeploy can automatically trigger a rollback when a CloudWatch alarm is breached, such as when error rates or latency exceed a threshold. This reduces the risk of a failed deployment by reverting to the last known good state without manual intervention. Option B is correct because a canary deployment shifts a small percentage of traffic to the new version first, allowing you to monitor for issues before routing all traffic, minimizing blast radius.

Exam trap

The trap here is that candidates often confuse manual approval (a pre-deployment gate) with a rollback mechanism, or they mistakenly think disabling health checks reduces false positives, when in fact health checks are critical for detecting failures during deployment.

107
Multi-Selecthard

A company is implementing a CI/CD pipeline for a containerized application using Amazon ECS and AWS CodePipeline. The team wants to ensure zero-downtime deployments. Which THREE strategies should the team implement? (Choose THREE.)

Select 3 answers
A.Use a blue/green deployment strategy with an Application Load Balancer.
B.Use a rolling update with a fixed batch size of 100% of tasks.
C.Use ECS service auto scaling to maintain desired count during deployment.
D.Configure the ECS service with health check grace period.
E.Stop all existing tasks before starting new tasks.
AnswersA, C, D

A blue/green deployment provisions an entirely new (green) set of ECS tasks alongside the running (blue) set, and the ALB shifts traffic over only once the green tasks pass health checks. Because the old environment stays live until cutover, users never hit a moment with zero healthy targets, and rollback is instant by simply routing back to blue.

Why this answer

Option A is correct because a blue/green deployment with an Application Load Balancer lets CodeDeploy shift traffic from the original ECS task set to the new (green) task set only after the new tasks pass health checks, and it can roll back instantly if validation fails, so users never hit a failed deployment. Option C is correct because ECS service auto scaling keeps the desired task count at the level the service needs during and after deployment, ensuring enough healthy tasks remain registered with the load balancer to absorb traffic while replacements are being launched. Option D is correct because the health check grace period prevents ECS from killing newly started tasks before they have finished booting and begun responding to ALB health checks, avoiding false unhealthy verdicts that would otherwise cause task churn and downtime.

Option B is not appropriate because a rolling update with a batch size of 100% replaces all tasks at once, which removes all healthy capacity simultaneously and can cause an outage. Option E is not appropriate because stopping all existing tasks before starting new ones creates a hard outage, directly violating the zero-downtime requirement.

Exam trap

The trap is selecting options that sound like they improve deployment but actually cause downtime, such as 'rolling update with 100% batch size' or 'stop all tasks first'; candidates must recognize that zero-downtime requires maintaining capacity and gradually shifting traffic.

108
MCQeasy

A developer is deploying a serverless application using AWS SAM. The application includes an API Gateway endpoint and a Lambda function. The developer wants to ensure that the Lambda function can be invoked only by the API Gateway and not directly. Which configuration should be used?

A.Configure a VPC endpoint policy that allows only API Gateway.
B.Add a resource-based policy with 'aws:SourceAccount' condition.
C.Add a resource-based policy with 'aws:SourceVpce' condition set to the API Gateway VPC endpoint ID.
D.Add a resource-based policy with 'aws:SourceArn' condition set to the API Gateway ARN.
AnswerD

Adding a resource-based policy with an `aws:SourceArn` condition set to the specific API Gateway ARN is the most effective and secure method to restrict Lambda function invocation. This policy ensures that only requests originating from that particular API Gateway instance (e.g., `arn:aws:execute-api:region:account-id:api-id/*/*`) are authorized to invoke the Lambda function. This fine-grained control prevents unauthorized direct invocations of the Lambda function, enforcing that all traffic must flow through the API Gateway.

Why this answer

Adding a resource-based policy with an `aws:SourceArn` condition set to the API Gateway ARN ensures that the Lambda function can only be invoked by that specific API Gateway. This uses the AWS Identity and Access Management (IAM) condition key to restrict the `lambda:InvokeFunction` action based on the ARN of the invoking resource, preventing direct invocation from other sources like the AWS CLI or SDK.

Exam trap

The trap here is that candidates confuse resource-based policies with VPC-based controls, often selecting `aws:SourceVpce` (Option C) thinking API Gateway invokes Lambda through a VPC endpoint, but API Gateway uses a public endpoint or private integration without a VPC endpoint for Lambda invocation.

How to eliminate wrong answers

Option A is wrong because a VPC endpoint policy controls traffic through a VPC endpoint, not invocation permissions for Lambda; it does not restrict which service can invoke the function. Option B is wrong because `aws:SourceAccount` condition only checks the AWS account ID of the caller, not the specific resource (API Gateway), so any service in the same account could still invoke the function. Option C is wrong because `aws:SourceVpce` condition checks for a VPC endpoint ID, but API Gateway does not use a VPC endpoint for invocation; it uses a public endpoint or a private integration, making this condition ineffective.

109
Matchingmedium

Match each HTTP status code to its meaning.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

OK

Created

Bad Request

Forbidden

Internal Server Error

Why these pairings

Correct matches: 200 OK, 404 Not Found, 500 Internal Server Error. Common confusions include mixing 200 and 201, or 404 and 403.

110
MCQhard

Refer to the exhibit. A developer tried to create a CloudFormation stack that includes an EC2 instance. The stack creation failed and rolled back. What should the developer do to get more details about the failure?

A.Review the CloudFormation template syntax.
B.Use the `detect-stack-drift` command.
C.Run `aws cloudformation describe-stack-events` for the stack.
D.Update the stack with the same template to see the error.
AnswerC

describe-stack-events returns the chronological, resource-by-resource event log including the exact CREATE_FAILED status reason (such as an invalid AMI ID, insufficient IAM permissions, or a capacity error) for each logical resource, making it the direct way to identify the root cause.

Why this answer

When a CloudFormation stack fails and rolls back, the authoritative source of failure details is the stack events log. Running aws cloudformation describe-stack-events returns the ordered event stream, including the specific resource that failed and the status reason containing the underlying error message.

Exam trap

DVA-C02 often tests whether candidates know that stack events (not template syntax or drift detection) contain the runtime failure reason, and candidates sometimes pick drift detection because it sounds diagnostic.

How to eliminate wrong answers

Option A is wrong because reviewing template syntax alone does not reveal runtime failures such as insufficient IAM permissions, AMI not found, or subnet capacity issues that occur during resource creation. Option B is wrong because detect-stack-drift compares actual resource configuration against the template and is unrelated to diagnosing a failed creation. Option D is wrong because re-updating with the same template would fail again and does not surface the original error details any better than the events log.

111
MCQmedium

A CodePipeline source stage should start when code is pushed to a repository, without scheduled polling. Which integration pattern should be used?

A.Manual approval only
B.Event-based trigger from the source provider/EventBridge integration
C.A cron job on an EC2 instance
D.CloudWatch Logs Insights
AnswerB

AWS CodePipeline natively supports event-based triggers from integrated source providers such as AWS CodeCommit, GitHub, and Amazon S3. For CodeCommit, a push to a repository branch generates an event that is published to Amazon EventBridge. An EventBridge rule can then be configured to detect this specific event and automatically invoke the CodePipeline, ensuring the pipeline starts immediately upon a code push, which is the most direct and efficient solution.

Why this answer

AWS CodePipeline can integrate with Amazon EventBridge to listen for repository events (e.g., push events from CodeCommit, GitHub, or Bitbucket) and automatically start the pipeline. This event-driven pattern eliminates the need for scheduled polling, providing near-instantaneous execution when code changes are detected.

Exam trap

The trap here is that candidates may confuse manual approval (a pipeline action) with a trigger mechanism, or assume that CloudWatch Logs Insights can initiate pipeline executions, when in fact only EventBridge or webhook-based integrations provide the required event-driven, polling-free source trigger.

How to eliminate wrong answers

Option A is wrong because manual approval is a gate that pauses pipeline execution for human review, not a mechanism to trigger the pipeline on code push. Option C is wrong because a cron job on an EC2 instance would require custom scripting, polling the repository periodically, and introduces unnecessary complexity, latency, and maintenance overhead compared to a native event-driven integration. Option D is wrong because CloudWatch Logs Insights is a query tool for analyzing log data, not a trigger mechanism for CodePipeline source stages.

112
Multi-Selecteasy

Which TWO are valid deployment strategies supported by AWS CodeDeploy? (Choose TWO.)

Select 2 answers
A.Immutable deployment
B.In-place deployment
C.Canary deployment
D.All at once deployment
E.Blue/Green deployment
AnswersB, E

In-place deployment is a valid deployment strategy supported by AWS CodeDeploy, where the application on the existing set of EC2 instances or on-premises servers is directly updated. During this process, CodeDeploy stops the application on each instance, deploys the new application revision, and then restarts the application. Traffic is not shifted between different environments; instead, the application files on the active servers are modified in place, potentially causing brief service interruptions on individual instances as they are updated.

Why this answer

AWS CodeDeploy supports in-place deployments (option B) where the application is updated on the existing instances without provisioning new ones. This is a valid deployment strategy that updates the current fleet by stopping and starting the application, and it is one of the two core strategies explicitly documented by AWS.

Exam trap

The trap here is that candidates confuse deployment strategies (in-place and blue/green) with deployment configuration options (like AllAtOnce) or with strategies from other AWS services (like immutable deployments in Elastic Beanstalk), leading them to select 'All at once' or 'Immutable' as valid CodeDeploy strategies.

113
Multi-Selecthard

A developer is deploying a new version of an AWS Lambda function. The function is behind an API Gateway endpoint. The developer wants to use canary deployments to gradually shift traffic to the new version. Which TWO steps should the developer perform?

Select 2 answers
A.Create a Lambda alias that points to the current version and configure routing to shift a percentage of traffic to the new version.
B.Configure Amazon CloudFront to distribute traffic between two API Gateway endpoints.
C.Update the API Gateway integration to point to the Lambda alias instead of a specific version.
D.Update the Lambda function code and publish a new version.
E.Create a new API Gateway stage for the new version and update DNS.
AnswersA, C

An AWS Lambda alias provides a stable endpoint for your function while allowing you to manage traffic distribution across different versions. By configuring the alias to point to both the current and the new Lambda versions with a weighted routing strategy, a developer can gradually shift a small percentage of traffic to the new version. This enables a controlled canary deployment, allowing for real-time monitoring and quick rollback if issues arise, minimizing impact on users.

Why this answer

Lambda aliases support traffic shifting for canary deployments by allowing you to route a percentage of incoming requests to a new function version while the majority continues to the current version. This is done by configuring the alias's routing configuration with a `RoutingConfig` that specifies the new version and the weight (e.g., 5%) of traffic it should receive. This enables gradual, controlled rollouts without modifying the API Gateway integration endpoint.

Option C is also necessary because the API Gateway integration must point to the Lambda alias (rather than a fixed version) so that the routing configuration on the alias can take effect. Without updating the integration to use the alias, API Gateway would continue to invoke a specific version directly, bypassing the canary routing.

Exam trap

The trap here is that candidates often think canary deployments require separate infrastructure (like CloudFront or multiple stages), but AWS Lambda aliases with routing configuration provide a built-in, serverless-native mechanism for percentage-based traffic shifting without additional services.

114
Drag & Dropmedium

Drag and drop the steps to set up a custom domain for an API Gateway API in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First have a domain, get a certificate, create custom domain in API Gateway, map to stage, and update DNS.

115
MCQeasy

An e-commerce platform uses AWS CodePipeline to deploy a web application to an Auto Scaling group behind an Application Load Balancer. The deployment strategy must minimize downtime and allow immediate rollback if the new version fails health checks. Which deployment configuration meets these requirements?

A.Use blue/green deployment with an immutable infrastructure.
B.Use all-at-once deployment to the Auto Scaling group.
C.Use canary deployment shifting 10% traffic for 5 minutes.
D.Use in-place rolling update with a batch size of 50%.
AnswerA

Blue/green deployment with immutable infrastructure creates an entirely new, identical environment (green) with the updated application version, leaving the existing production environment (blue) untouched. Once the green environment passes all health checks and tests, traffic is atomically shifted from blue to green. This strategy ensures zero downtime during deployment and provides an instant rollback capability by simply reverting traffic back to the healthy, unchanged blue environment if any issues arise with the new version.

Why this answer

Blue/green deployment with immutable infrastructure minimizes downtime by running the new version (green) alongside the old (blue) and switching traffic only after health checks pass. If the new version fails, rollback is immediate by routing traffic back to the blue environment without redeploying. AWS CodePipeline supports this via CodeDeploy with a blue/green configuration, ensuring zero-downtime deployments and instant rollback capability.

Exam trap

The trap here is that candidates confuse canary or rolling updates with immediate rollback capability, but only blue/green provides an instant traffic switch without redeployment, as the old environment remains intact.

How to eliminate wrong answers

Option B is wrong because all-at-once deployment replaces all instances simultaneously, causing downtime during the deployment and no ability to rollback without redeploying the old version. Option C is wrong because canary deployment shifts only 10% traffic for 5 minutes, which does not guarantee immediate rollback of the entire fleet if the new version fails; it requires manual or automated traffic shifting back, which is not instantaneous. Option D is wrong because in-place rolling update with a batch size of 50% replaces instances gradually but still causes partial downtime and requires a full redeployment to rollback, as the old instances are terminated during the update.

116
Multi-Selectmedium

Which TWO actions can be taken to enable automatic rollback for an AWS CloudFormation stack update that fails? (Select TWO.)

Select 2 answers
A.Set the '--on-failure' parameter to 'ROLLBACK' during stack update.
B.Specify a CloudWatch alarm in the '--rollback-configuration' parameter during stack update.
C.Use a change set to review the changes before updating.
D.Apply a stack policy that denies updates to critical resources.
E.Set the '--disable-rollback' parameter to 'false' during stack update.
AnswersB, E

Specifying a CloudWatch alarm within the '--rollback-configuration' parameter during a stack update is a powerful mechanism for enabling automatic rollback. This configuration allows CloudFormation to monitor the specified alarm(s) for a defined period after the update completes. If any of these alarms transition into an ALARM state, CloudFormation will automatically initiate a rollback of the stack to its previous stable state, ensuring operational stability.

Why this answer

The `--rollback-configuration` parameter allows you to specify a CloudWatch alarm that, when triggered during a stack update, automatically initiates a rollback. This is the intended mechanism for monitoring-based automatic rollback, as CloudFormation will monitor the alarm state and revert the update if the alarm enters the ALARM state. Option E is correct because setting `--disable-rollback` to `false` explicitly enables automatic rollback on any stack update failure, which is the default behavior but can be explicitly configured for clarity.

Exam trap

The trap here is that candidates confuse the `--on-failure` parameter (which only applies to stack creation) with stack update rollback, or they assume that a stack policy or change set can trigger automatic rollback, when in fact only `--rollback-configuration` and `--disable-rollback` control automatic rollback behavior during updates.

117
MCQeasy

A developer is using AWS CodeDeploy to deploy an application to an EC2 instance. The deployment fails with the error 'ScriptMissing' during the BeforeInstall lifecycle event. What is the most likely cause?

A.The BeforeInstall lifecycle event is not defined in the appspec.yml
B.The script file specified in the appspec.yml for the BeforeInstall hook is not present on the instance
C.The CodeDeploy agent on the instance is not running
D.The instance does not have the necessary permissions to execute the script
AnswerB

This is the correct explanation. When CodeDeploy executes a deployment, it first downloads the application revision to the instance. If the appspec.yml specifies a script for the BeforeInstall hook, and the CodeDeploy agent cannot locate that script file at the specified path within the downloaded revision on the target instance, it will explicitly fail with a "ScriptMissing" error. This error precisely indicates that the expected script file is physically absent from the instance's file system where the agent is looking.

Why this answer

The 'ScriptMissing' error in AWS CodeDeploy indicates that the deployment failed because a script file referenced in the appspec.yml for a lifecycle event (in this case, BeforeInstall) could not be found on the EC2 instance. CodeDeploy expects the script to be present at the specified path after the archive is extracted; if the file is missing or the path is incorrect, the agent reports this error. Option B correctly identifies that the script file is not present on the instance.

Exam trap

The trap here is that candidates confuse 'ScriptMissing' with permission issues or agent connectivity problems, but AWS CodeDeploy has distinct error codes for each failure mode, and 'ScriptMissing' specifically points to a missing file, not execution or agent status.

How to eliminate wrong answers

Option A is wrong because if the BeforeInstall lifecycle event is not defined in the appspec.yml, CodeDeploy would simply skip that event and not produce a 'ScriptMissing' error — the error specifically occurs when a hook is defined but its script is absent. Option C is wrong because if the CodeDeploy agent were not running, the deployment would fail with an 'AgentNotRunning' or 'InstanceUnreachable' error, not a 'ScriptMissing' error. Option D is wrong because insufficient permissions to execute the script would result in a 'ScriptFailed' error (e.g., exit code 126 or 127), not a 'ScriptMissing' error — the agent first checks for the file's existence before attempting execution.

118
MCQmedium

A developer is using AWS CloudFormation to deploy a stack that includes an Amazon EC2 instance with user data. The user data script installs software and configures the application. The developer wants to ensure that the stack creation waits for the user data script to complete before marking the stack as CREATE_COMPLETE. What should the developer do?

A.Add a DependsOn attribute to the EC2 instance resource.
B.Use a CloudFormation WaitCondition and a WaitConditionHandle.
C.Add a CreationPolicy with a timeout to the EC2 instance resource and use cfn-signal in the user data.
D.Configure the EC2 instance to run the user data script as a service.
AnswerC

Adding a `CreationPolicy` with a `ResourceSignal` property, including a `Timeout` and `Count`, to an EC2 instance resource instructs CloudFormation to wait for a specified number of success signals from the instance before marking its creation as complete. The `cfn-signal` helper script, executed within the instance's user data, sends these signals back to CloudFormation, indicating the successful completion of the user data script and any application setup. This ensures the instance is fully configured and ready before the stack proceeds.

Why this answer

The correct approach is to add a CreationPolicy to the EC2 instance resource and use cfn-signal in the user data script. The CreationPolicy tells CloudFormation to wait for a signal from the instance before considering the resource created. The user data script runs, installs software, and then calls cfn-signal to indicate success.

If the signal is not received within the timeout, the stack creation fails. Option A (DependsOn) only orders resource creation, not waits for user data. Option B (WaitCondition) is a legacy method that is more complex; CreationPolicy is the recommended modern approach.

Option D (running as a service) does not send any signal to CloudFormation.

119
MCQeasy

A developer is deploying a new version of a Lambda function using an AWS CodePipeline pipeline. The deployment fails during the 'Deploy' stage with an error indicating that the function's code is too large. What should the developer do to resolve this issue?

A.Upload the Lambda deployment package to Amazon S3 and reference it from the function
B.Increase the Lambda function's timeout setting
C.Use Amazon CloudFront to distribute the Lambda code
D.Enable AWS X-Ray tracing on the Lambda function
AnswerA

The AWS Lambda service imposes a direct upload limit of 50 MB for deployment packages. For larger codebases or dependencies, developers must upload the deployment package, which can be up to 250 MB unzipped, to an Amazon S3 bucket. Referencing the S3 object's key and version from the Lambda function configuration allows the service to retrieve the code, circumventing the direct upload size constraint and enabling successful deployment of substantial applications.

Why this answer

AWS Lambda has a hard limit of 50 MB for direct uploads via the console or API. When a deployment package exceeds this limit, the correct approach is to upload the package to Amazon S3 and configure the Lambda function to reference the S3 object. CodePipeline can then use the S3 location to deploy the function, bypassing the direct upload size restriction.

Exam trap

The trap here is that candidates may confuse Lambda's execution timeout or memory limits with the deployment package size limit, or incorrectly assume that CloudFront can serve as a storage backend for Lambda code.

How to eliminate wrong answers

Option B is wrong because increasing the timeout setting does not affect the deployment package size limit; timeouts control execution duration, not code storage. Option C is wrong because CloudFront is a content delivery network (CDN) for caching and distributing static content, not a service for storing or deploying Lambda code; it cannot resolve a code size limit. Option D is wrong because enabling X-Ray tracing adds monitoring and debugging capabilities but does not change the Lambda deployment package size quota.

120
Multi-Selecteasy

A company uses AWS CodeBuild to compile and test a Java application. The build process takes a long time because dependencies are downloaded every time. Which TWO actions can reduce build time? (Choose TWO.)

Select 2 answers
A.Increase the compute type of the build environment to have more CPU and memory.
B.Change the build runtime to a language that compiles faster.
C.Configure the build project to run builds in parallel.
D.Enable local caching in the CodeBuild project to reuse dependency files between builds.
E.Use Amazon S3 to cache dependencies and restore them at the start of each build.
AnswersD, E

Local caching in CodeBuild stores specific directories, such as /root/.m2 for Maven or /root/.gradle for Gradle, on the build instance's local disk, keyed by the project and optionally by a custom cache key. On subsequent builds, if the same instance is reused, downloaded dependency JARs are restored from the local cache instead of being fetched from the internet, eliminating the network latency that dominates a cold build. To make it effective, you must configure a cache key that changes only when dependencies actually change, so identical builds skip the download entirely.

Why this answer

Option D is correct because enabling local caching in the CodeBuild project (e.g., LOCAL_SOURCE_CACHE, LOCAL_DOCKER_LAYER_CACHE, or a local cache for dependency directories) lets CodeBuild retain downloaded dependencies on the build host between builds, so Maven/Gradle artifacts are not re-downloaded each time, directly cutting build duration. Option E is correct because CodeBuild supports S3 caching, where dependency files (such as the Maven ~/.m2 or Gradle ~/.gradle directories) are uploaded to an S3 bucket after a build and restored at the start of subsequent builds, eliminating repeated downloads even across fresh hosts. Option A is not correct because increasing compute type only adds CPU/memory and does not address the network-bound dependency download bottleneck, so it does not reliably reduce the time spent fetching dependencies.

Option B is not correct because changing the build runtime to a 'faster-compiling language' is not applicable—the application is Java and the runtime must support Java compilation. Option C is not correct because running builds in parallel increases throughput of multiple builds but does not shorten the duration of an individual build's dependency download phase.

Exam trap

DVA-C02 often tests the misconception that more compute or parallel builds solve slow builds, when the actual issue is repeated dependency downloads that require caching.

121
Multi-Selecteasy

Which TWO deployment methods can be used to update an AWS Lambda function with no downtime? (Select TWO.)

Select 2 answers
A.Update the function code using update-function-code.
B.Use a weighted alias to gradually shift traffic to a new version.
C.Create a new version and update the alias to point to the new version.
D.Create a new Lambda function and delete the old one.
E.Update the function configuration to increase memory.
AnswersB, C

This deployment method enables a canary release strategy, ensuring zero downtime. A new Lambda function version is published, and an alias is configured to distribute traffic between the existing stable version and the new version based on specified weights (e.g., 90% old, 10% new). This allows for gradual rollout, real-time monitoring of the new version's performance, and immediate rollback by adjusting weights if issues arise.

Why this answer

A weighted alias allows you to route a small percentage of traffic to a new Lambda version while keeping the majority on the current version, enabling canary deployments with zero downtime. Option C is correct because creating a new version and updating the alias to point to it performs an instant, atomic switch, ensuring all traffic is served by the new version without any interruption.

Exam trap

The trap here is that candidates often think update-function-code is a safe deployment method, but it modifies the mutable $LATEST version, which can cause downtime if an alias points to $LATEST and the update is not atomic.

122
MCQmedium

A developer is using AWS CodeDeploy to deploy an application to an Auto Scaling group of EC2 instances. The developer wants to minimize the number of instances that are taken out of service at any given time during the deployment. Which predefined deployment configuration should the developer use?

A.AllAtOnce
B.OneAtATime
C.HalfAtATime
D.Custom with 50% at a time
AnswerB

The OneAtATime deployment configuration updates instances sequentially, taking only one instance out of service at any given moment while the remaining instances continue to serve traffic. This rolling update strategy ensures that the application maintains high availability throughout the deployment process, significantly minimizing the impact on end-users. It is the most effective method for ensuring continuous service and reducing downtime in an Auto Scaling environment.

Why this answer

The OneAtATime deployment configuration shifts traffic to one new instance at a time, ensuring that only a single instance is taken out of service during the deployment. This minimizes the number of instances removed from the Auto Scaling group at any given moment, which directly meets the developer's requirement to reduce service disruption.

Exam trap

The trap here is that candidates might think 'HalfAtATime' is not a predefined configuration, but AWS CodeDeploy does offer 'HalfAtATime' as a predefined option. However, 'HalfAtATime' takes half the instances out of service at once, which does not minimize the number. The correct choice to minimize instances taken out of service is 'OneAtATime'.

How to eliminate wrong answers

Option A (AllAtOnce) is wrong because it deploys to all instances simultaneously, taking the entire fleet out of service at once, which maximizes disruption. Option C (HalfAtATime) is wrong because it is not a predefined deployment configuration in AWS CodeDeploy; the correct predefined option for deploying to half the instances is 'HalfAtATime' but it would take 50% of instances out of service at a time, which is more than the single instance the developer wants. Option D (Custom with 50% at a time) is wrong because while custom configurations are possible, the developer specifically asked for a predefined configuration, and using a custom one would not be the simplest or most direct solution; moreover, deploying 50% at a time would still take more instances out of service than the desired minimum.

123
MCQmedium

A developer manages a web application deployed on an AWS Elastic Beanstalk environment with multiple Amazon EC2 instances. The developer needs to deploy a new version of the application with zero downtime. The new version requires a different instance type and additional software packages. Which deployment strategy should the developer use?

A.Rolling
B.All at once
C.Rolling with additional batch
D.Immutable
AnswerD

Immutable deployment creates a new set of instances with the updated application version and any configuration changes, including instance type. It launches the new instances in a temporary Auto Scaling group, then swaps them with the old ones, ensuring zero downtime. This strategy meets both requirements: zero downtime and a different instance type.

Why this answer

Immutable deployment is the only strategy that supports changing instance types and other configuration settings while maintaining zero downtime. It creates a full new set of instances with the new configuration, then swaps them in. Other strategies either cause downtime or cannot alter the environment's instance type.

Exam trap

The trap here is assuming that rolling with additional batch can change instance types because it adds instances, but it only adds instances of the same type.

124
MCQmedium

A developer is deploying a static website to Amazon S3. The website uses client-side JavaScript to make API calls to an AWS Lambda function via Amazon API Gateway. The developer wants to enable cross-origin resource sharing (CORS) on the API Gateway to allow the S3 website to make requests. After enabling CORS on the API Gateway and redeploying the API, the browser still reports CORS errors. The developer checks the API Gateway configuration and sees that the OPTIONS method is not defined. The developer has already enabled CORS via the API Gateway console, which should have created the OPTIONS method. However, it did not appear. What should the developer do to resolve the issue?

A.Update the JavaScript in the website to use a different HTTP method.
B.Update the S3 bucket policy to allow cross-origin requests from any origin.
C.Modify the Lambda function to return CORS headers in its response.
D.Manually add an OPTIONS method to the API Gateway resource and configure the CORS headers in the integration response.
AnswerD

To resolve CORS issues, API Gateway must be explicitly configured to handle the browser's preflight OPTIONS request. This involves manually adding an OPTIONS method to the API Gateway resource and setting up a mock integration response that includes the required Access-Control-Allow-Origin, Access-Control-Allow-Methods, and Access-Control-Allow-Headers in its headers, allowing the browser to proceed with the actual request.

Why this answer

When API Gateway's CORS console feature fails to create the OPTIONS method (often due to permissions, resource policy conflicts, or the resource already having a mock integration), the developer must manually create an OPTIONS method on the resource, set the integration type to MOCK, and configure the integration response with the Access-Control-Allow-Origin, Access-Control-Allow-Headers, and Access-Control-Allow-Methods headers. The browser's preflight request (OPTIONS) must receive those headers before the actual GET/POST is sent, so a missing OPTIONS method guarantees CORS failure regardless of what the backend returns.

Exam trap

DVA-C02 often tests the misconception that enabling CORS in the console is always sufficient, when in fact the OPTIONS method must exist and return the correct headers for the preflight to succeed.

How to eliminate wrong answers

Option A is wrong because changing the HTTP method does not bypass the browser's CORS preflight requirement — any non-simple request still triggers an OPTIONS preflight. Option B is wrong because S3 bucket policies govern access to S3 objects, not cross-origin permissions for API Gateway responses; CORS is enforced by the browser based on headers returned by the API. Option C is wrong because while Lambda can return CORS headers on the actual response, the browser first sends a preflight OPTIONS request that never reaches Lambda if the OPTIONS method is undefined, so the preflight fails before the Lambda response matters.

125
Multi-Selecteasy

Which TWO are benefits of using AWS CloudFormation for infrastructure deployment? (Choose two.)

Select 2 answers
A.Infrastructure is provisioned consistently across environments.
B.Automatically enforces compliance rules.
C.Automatically rolls back changes if stack creation fails.
D.Replaces the need for a CI/CD pipeline.
E.Provides real-time monitoring of deployed resources.
AnswersA, C

CloudFormation templates define infrastructure as code, specifying resources and their configurations in a declarative manner. By using the same template across development, staging, and production environments, organizations ensure that the infrastructure deployed in each environment is identical and provisioned consistently. This eliminates configuration drift and reduces human error, leading to more reliable and predictable deployments.

Why this answer

AWS CloudFormation uses templates to define infrastructure as code, ensuring that the same set of resources is provisioned identically across multiple environments (e.g., dev, test, prod). This eliminates configuration drift and manual errors by applying the same template consistently, which is a core benefit of infrastructure as code.

Exam trap

The trap here is that candidates often confuse CloudFormation's rollback-on-failure behavior (which is automatic by default) with compliance enforcement or monitoring, leading them to select Option B or E, but CloudFormation does not natively audit or monitor resources.

126
MCQhard

A company uses AWS CodePipeline to automate deployments. The pipeline source stage uses Amazon S3. The developer wants to automatically trigger the pipeline when a new version of the source file is uploaded. The developer has configured S3 event notifications to invoke a Lambda function that starts the pipeline. However, the pipeline is not triggering. What is the most likely cause?

A.S3 versioning is not enabled on the bucket.
B.The pipeline execution role does not have permission to read from the S3 bucket.
C.The Lambda function does not have permission to start the pipeline.
D.The S3 bucket does not have a bucket policy that allows S3 to invoke Lambda.
AnswerC

This would cause an error, but the question says the pipeline is not triggering, implying no invocation.

Why this answer

The most likely cause is that the Lambda function does not have permission to start the pipeline. S3 event notifications can invoke Lambda regardless of whether S3 versioning is enabled, so versioning is not required. For the pipeline to start, the Lambda function's execution role must have permission to call codepipeline:StartPipelineExecution on the target pipeline.

If that permission is missing, the S3 event will invoke Lambda but the pipeline will not start. (Note: the S3 bucket must also allow S3 to invoke the Lambda function; however, among the provided options, the missing Lambda permission to start the pipeline is the most likely cause.)

Exam trap

The trap is assuming that S3 versioning is required for S3 event notifications or CodePipeline S3 source actions. S3 event notifications work without versioning, and CodePipeline can use S3 sources without requiring versioning. Focus on the IAM permissions needed for the Lambda function to start the pipeline.

How to eliminate wrong answers

Option B is wrong because the pipeline execution role's permission to read from the S3 bucket is not the issue; the pipeline is not triggering at all, which points to the detection mechanism, not read permissions. Option C is wrong because the Lambda function's permission to start the pipeline is a separate concern; if the function is invoked but fails to start the pipeline, you would see invocation errors, but the question states the pipeline is not triggering, implying the event notification itself is failing. Option D is wrong because S3 does not require a bucket policy to invoke Lambda; instead, the Lambda function's resource-based policy must grant S3 permission to invoke it, and the question does not indicate that the Lambda function is not being invoked.

127
Multi-Selectmedium

A developer is deploying an application using AWS CloudFormation. The stack includes an Amazon RDS DB instance. To ensure secure credential management, which TWO actions should the developer take? (Choose TWO.)

Select 2 answers
A.Use AWS Systems Manager Parameter Store with a SecureString parameter for the password.
B.Use AWS Secrets Manager to store the master password and reference it dynamically.
C.Hardcode the master password in the CloudFormation template.
D.Use IAM database authentication to manage credentials.
E.Leave the master password empty so that CloudFormation generates a random password.
AnswersA, B

Using AWS Systems Manager Parameter Store with a SecureString parameter is a robust solution for storing sensitive data like passwords. SecureString parameters are encrypted at rest using AWS Key Management Service (KMS) and can be securely referenced within CloudFormation templates using dynamic references or `Fn::Sub` functions. This method ensures the password is never exposed in plain text within the template or CloudFormation console, adhering to security best practices for non-rotating secrets.

Why this answer

AWS Systems Manager Parameter Store with a SecureString parameter is correct because it allows you to securely store the RDS master password as an encrypted parameter and reference it in the CloudFormation template using the `resolve:ssm` or `resolve:ssm-secure` dynamic reference. This avoids hardcoding the password in the template or exposing it in plaintext, while still enabling automated deployment.

Exam trap

The trap here is that candidates may confuse IAM database authentication (which handles user-level access) with master password management, or assume CloudFormation can auto-generate passwords for RDS, but neither is correct for securely setting the initial master password.

128
MCQhard

Refer to the exhibit. A developer is troubleshooting a failed CodeDeploy deployment to an EC2 Auto Scaling group. The instance logs show that the 'BeforeInstall' script failed with exit code 1. What should the developer do to resolve the issue?

A.Review the BeforeInstall script for errors and fix them.
B.Ensure the CodeDeploy agent is installed and running on the instance.
C.Verify that the scripts location in the AppSpec file is correct.
D.Check that the instance's IAM role has permissions to download the revision.
AnswerA

An exit code of 1 from a CodeDeploy lifecycle hook script, such as `BeforeInstall`, explicitly indicates that the script itself encountered an error and terminated abnormally. This typically means there's a syntax error, a command failed, or a logical condition within the script was not met, preventing successful execution of its intended tasks. Troubleshooting should involve reviewing the script's contents, checking logs on the instance for specific error messages, and ensuring all commands within it are valid and executable in the target environment.

Why this answer

The 'BeforeInstall' script failed with exit code 1, which is a generic error indicating the script itself encountered an issue during execution. The developer should review the script for errors, such as syntax mistakes, missing dependencies, or incorrect commands, and fix them. This is the most direct and appropriate action because the failure is explicitly tied to the script's execution, not to infrastructure or permissions.

Exam trap

The trap here is that candidates may assume a script failure is always due to permissions or agent issues, but the exit code 1 specifically points to a script-level error, not infrastructure or configuration problems.

How to eliminate wrong answers

Option B is wrong because the CodeDeploy agent is already running (the instance logs show the script executed, which requires the agent), so reinstalling or checking the agent is unnecessary. Option C is wrong because if the script location in the AppSpec file were incorrect, the script would not have run at all, but the logs confirm it executed and failed. Option D is wrong because the instance successfully downloaded the revision (the script ran), so the IAM role permissions are sufficient; a permissions issue would prevent the download, not cause a script exit code 1.

129
MCQmedium

A developer is using AWS CodeDeploy to deploy a new version of a web application to an Auto Scaling group of Amazon EC2 instances. The deployment must install dependencies and run a script to start the application after the new revision is copied to the instance. The developer has created an appspec.yml file with the necessary hooks. Which of the following must the developer ensure to allow CodeDeploy to execute the scripts on the instances?

A.The developer must store the application revision in an Amazon S3 bucket and grant the EC2 instances direct read access to that bucket so they can download and execute the scripts.
B.The instances must be associated with a security group that allows inbound traffic on port 22 from the CodeDeploy service IP range so that CodeDeploy can SSH into the instances and run the scripts.
C.The CodeDeploy agent must be installed and running on the instances, and the instances must have an IAM instance profile that allows them to access the CodeDeploy service.
D.The developer must attach an IAM role to the CodeDeploy service role that allows it to execute scripts on the instances via AWS Systems Manager Run Command.
AnswerC

The CodeDeploy agent is required on each EC2 instance to receive deployment commands, copy the revision, and run lifecycle event hooks. The instance profile grants permissions to communicate with CodeDeploy and retrieve deployment artifacts, which is essential for successful deployments in an Auto Scaling group.

Why this answer

For CodeDeploy to deploy to EC2 instances, the CodeDeploy agent must be installed and running on each instance. The instances also need an IAM instance profile that grants permissions to communicate with CodeDeploy and retrieve deployment artifacts. This setup allows CodeDeploy to orchestrate the deployment and run lifecycle hooks defined in appspec.yml.

Exam trap

The trap here is assuming that CodeDeploy uses SSH or Systems Manager to execute scripts, when it actually relies on an agent installed on the instances.

130
Multi-Selectmedium

Which THREE are best practices for deploying applications with AWS Elastic Beanstalk? (Choose THREE.)

Select 3 answers
A.Manually update EC2 instances in the environment.
B.Use environment configuration files (.ebextensions) to manage settings.
C.Use a blue/green deployment to minimize downtime.
D.Deploy to a staging environment before production.
E.Always use the default Elastic Beanstalk domain for production.
AnswersB, C, D

Utilizing `.ebextensions` configuration files is a fundamental best practice for Elastic Beanstalk deployments. These YAML or JSON files allow developers to customize and extend the environment by defining custom resources, installing packages, modifying server configurations, and running scripts. This declarative approach ensures that every deployment consistently applies the desired settings and infrastructure modifications, promoting repeatability and reducing configuration drift across environments.

Why this answer

Ebextensions configuration files allow you to define environment settings, software configurations, and custom resources declaratively, ensuring consistent and repeatable deployments without manual intervention. This aligns with the best practice of infrastructure as code, as Elastic Beanstalk automatically applies these settings during environment creation and updates.

Exam trap

The trap here is that candidates may think manual EC2 updates (Option A) are acceptable for quick fixes, but Elastic Beanstalk's managed updates and immutable deployments are designed to prevent configuration drift and ensure environment consistency.

131
MCQeasy

A developer is using AWS CodeBuild to compile and package a Java application. The build process takes longer than expected. The developer wants to speed up the build by reusing dependencies that have not changed between builds. Which feature should the developer enable?

A.Configure the build project to run builds concurrently
B.Enable build artifacts in the CodeBuild project
C.Enable caching for the CodeBuild project by specifying an S3 bucket for cache storage
D.Store the build's output artifacts in an S3 bucket
AnswerC

Enabling caching for the CodeBuild project by specifying an S3 bucket for cache storage is the intended solution: CodeBuild downloads a cache archive from the given S3 bucket before the build and uploads it again afterward. This lets package managers like Maven, Gradle, npm, or pip reuse previously downloaded dependencies, dramatically reducing build time and network traffic for untouched dependencies. You can configure cache paths in the buildspec to collect and restore the correct directories. This is the standard, documented way to cache dependencies in CodeBuild.

Why this answer

AWS CodeBuild caching allows you to persist dependencies (e.g., Maven .m2 repository, Gradle caches) between builds. By specifying an S3 bucket as the cache storage, CodeBuild uploads the cache after a successful build and downloads it at the start of subsequent builds, avoiding re-downloading unchanged dependencies. This significantly reduces build time for Java applications.

Exam trap

DVA-C02 often tests the confusion between caching (for dependencies) and artifacts (for build outputs), leading candidates to choose artifact-related options when asked about speeding up builds by reusing dependencies.

How to eliminate wrong answers

Option A is wrong because running builds concurrently increases throughput but does not reduce the time of an individual build; it may even increase resource contention. Option B is wrong because build artifacts are the output of the build (e.g., JAR files) and do not affect dependency resolution speed. Option D is wrong because storing output artifacts in S3 is for post-build storage and distribution, not for caching dependencies to speed up builds.

132
MCQeasy

A developer is deploying a serverless application using AWS SAM. The application includes an API Gateway REST API and a Lambda function. The developer wants to set up a custom domain name for the API in the production stage. Which resource should the developer define in the SAM template to achieve this with minimal effort?

A.AWS::ApiGateway::DomainName
B.AWS::Serverless::Api
C.AWS::ApiGateway::BasePathMapping
D.AWS::Route53::RecordSet
AnswerB

The AWS::Serverless::Api resource in AWS SAM provides a high-level abstraction for defining an Amazon API Gateway REST API, including its custom domain configuration. By utilizing its `Domain` property, developers can specify a custom domain name, a certificate ARN from AWS Certificate Manager (ACM), and base path mappings directly within the SAM template. SAM then automatically provisions the underlying `AWS::ApiGateway::DomainName` and `AWS::ApiGateway::BasePathMapping` CloudFormation resources, simplifying the setup of custom domains for serverless APIs.

Why this answer

The AWS::Serverless::Api resource in an AWS SAM template provides a high-level abstraction that simplifies the configuration of API Gateway REST APIs, including the ability to set up a custom domain name via the Domain property. This approach requires minimal effort because SAM automatically creates the underlying AWS::ApiGateway::DomainName and AWS::ApiGateway::BasePathMapping resources, handles the TLS certificate association, and manages the stage deployment. Defining a raw AWS::ApiGateway::DomainName would require additional manual configuration for base path mapping and stage integration, making the Serverless::Api the most efficient choice.

Exam trap

The trap here is that candidates often think they must define the low-level AWS::ApiGateway::DomainName resource directly, overlooking that AWS SAM's AWS::Serverless::Api provides a built-in Domain property that automates the entire custom domain setup with minimal code.

How to eliminate wrong answers

Option A is wrong because AWS::ApiGateway::DomainName only defines the custom domain name and its TLS certificate; it does not automatically create the base path mapping or integrate with the API stage, so additional resources and manual wiring are needed. Option C is wrong because AWS::ApiGateway::BasePathMapping maps a base path to an API stage but does not create the custom domain name itself; it must be used in conjunction with a DomainName resource, increasing complexity. Option D is wrong because AWS::Route53::RecordSet creates a DNS record (e.g., CNAME or A alias) to point a custom domain to the API Gateway endpoint, but it does not configure the API Gateway custom domain name or TLS termination; it is a DNS-only resource and cannot replace the DomainName configuration.

133
Multi-Selecteasy

A company is deploying a web application on AWS Elastic Beanstalk. The application uses an Amazon RDS database. The company wants to ensure that database credentials are not exposed in the application code or environment variables. Which TWO methods are secure ways to manage credentials? (Choose TWO.)

Select 2 answers
A.Store credentials in AWS Secrets Manager and retrieve them at runtime.
B.Store credentials in an Amazon S3 bucket with server-side encryption.
C.Hardcode credentials in the application configuration file.
D.Store credentials in AWS Systems Manager Parameter Store with SecureString parameter type.
E.Store credentials as environment variables in the Elastic Beanstalk environment.
AnswersA, D

AWS Secrets Manager encrypts secrets with KMS keys and provides a dedicated GetSecretValue API for runtime retrieval, so application code never contains or resolves the secret itself. It also supports automatic rotation of database credentials via Lambda, fine-grained IAM policies, and cross-account access, making it the most built-for-purpose option for dynamically fetching secrets in an Elastic Beanstalk environment.

Why this answer

Option A is correct because AWS Secrets Manager is purpose-built for storing and rotating secrets such as RDS database credentials, and the application can retrieve them at runtime via the AWS SDK using IAM permissions, so the credentials never appear in code or environment variables. Option D is correct because AWS Systems Manager Parameter Store supports the SecureString parameter type, which encrypts values with AWS KMS and allows retrieval at runtime through IAM-controlled API calls, keeping credentials out of the application code and environment variables. Option B is not appropriate because an S3 object, even with server-side encryption, is not a dedicated secrets-management service and would still require custom retrieval logic and careful access controls to avoid exposure.

Option C is wrong because hardcoding credentials in a configuration file directly exposes them in source control and deployment artifacts. Option E is wrong because Elastic Beanstalk environment variables are visible in the console and configuration and are explicitly what the scenario wants to avoid.

Exam trap

DVA-C02 often tests whether candidates recognize that environment variables and S3-stored secrets are not secure credential stores, luring them toward 'encrypted S3' as if encryption alone made it a secrets manager.

134
MCQmedium

A company uses AWS CodePipeline to deploy a static website to Amazon S3. The pipeline has a source stage from CodeCommit, a build stage using CodeBuild, and a deploy stage that uses S3 deployment action. The website is served via Amazon CloudFront. After a successful pipeline run, the updated files are in S3, but CloudFront still serves old content. What is the MOST efficient solution?

A.Manually create a CloudFront invalidation after each deployment.
B.Reduce the CloudFront distribution's default TTL to 0.
C.Add a post-deploy invalidation step in CodePipeline to create a CloudFront invalidation.
D.Update the S3 bucket policy to allow public read access.
AnswerC

CloudFront caches objects at edge locations until the TTL expires, so new S3 objects are not served immediately. Creating an invalidation for the changed paths forces edge caches to refetch from the origin, satisfying the requirement for fresh content efficiently.

Why this answer

It automates the creation of a CloudFront invalidation as part of the CodePipeline post-deploy stage. This ensures that after new files are uploaded to S3, CloudFront's edge caches are purged of the old content, forcing it to fetch the updated files from the origin. This is the most efficient solution as it requires no manual intervention and does not compromise caching performance.

Exam trap

The trap here is that candidates may think reducing TTL to 0 is a valid solution, but this ignores the fact that TTL controls how long objects are cached, not how to purge already-cached content, and it would severely degrade CDN performance.

How to eliminate wrong answers

Option A is wrong because manually creating a CloudFront invalidation after each deployment is inefficient, error-prone, and does not scale; it also contradicts the goal of an automated CI/CD pipeline. Option B is wrong because setting the default TTL to 0 would force CloudFront to re-fetch every object from the origin on every request, defeating the purpose of a CDN and significantly increasing latency and origin load. Option D is wrong because the S3 bucket policy for public read access is unrelated to CloudFront cache invalidation; CloudFront can serve private S3 content via Origin Access Control (OAC) and still serve stale cached content.

135
MCQhard

A developer is using AWS CodeDeploy with a blue/green deployment strategy for an EC2 Auto Scaling group. The deployment must automatically roll back if any of the new instances fail a health check within the first 10 minutes after deployment. Which configuration should the developer set?

A.Set the deployment configuration to 'CodeDeployDefault.EC2AllAtOnce'
B.Configure the deployment group to use an alarm-based rollback with a CloudWatch alarm on the ELB health check
C.Enable automatic rollback in the deployment group configuration and set the event to 'DEPLOYMENT_FAILURE' or 'DEPLOYMENT_STOP_ON_REQUEST'
D.Configure the deployment group with a 'LoadBalancerInfo' and enable 'originalInstanceTermination' for rollback
AnswerB

Configuring the deployment group with alarm-based rollback, specifically using a CloudWatch alarm on the ELB health check, is the correct and most robust solution for Blue/Green deployments. This approach allows CodeDeploy to monitor critical metrics from the ELB, such as the count of unhealthy hosts or HTTP 5xx errors, on the newly deployed environment. If the specified thresholds are breached, indicating application issues, the CloudWatch alarm will trigger CodeDeploy to automatically revert traffic to the original, stable environment, ensuring high availability and minimizing user impact.

Why this answer

The requirement is to automatically roll back based on health check failures within a specific time window after deployment. AWS CodeDeploy supports alarm-based rollbacks where you can configure a CloudWatch alarm that monitors the ELB health check status of the new instances. When the alarm triggers within the configured monitoring period (e.g., 10 minutes), CodeDeploy automatically rolls back the deployment to the previous version, meeting the exact condition described.

Exam trap

The trap here is that candidates often confuse deployment configuration settings (like traffic shifting speed) with rollback triggers, or assume that enabling automatic rollback for deployment failures alone will cover post-deployment health check failures, but CodeDeploy requires a separate alarm-based rollback configuration to monitor health after instances are in service.

How to eliminate wrong answers

Option A is wrong because 'CodeDeployDefault.EC2AllAtOnce' is a deployment configuration that controls the traffic shifting speed (all instances at once), not a rollback mechanism based on health checks. Option C is wrong because enabling automatic rollback for 'DEPLOYMENT_FAILURE' or 'DEPLOYMENT_STOP_ON_REQUEST' only triggers rollback on deployment failures or manual stops, not on post-deployment health check failures within a time window. Option D is wrong because 'LoadBalancerInfo' and 'originalInstanceTermination' are used to configure traffic routing and instance termination behavior in blue/green deployments, not to trigger automatic rollbacks based on health checks.

136
Multi-Selecteasy

A developer is using AWS SAM to deploy a serverless application. The developer wants to enable canary deployments for the Lambda function. Which TWO resources must be configured in the SAM template? (Choose TWO.)

Select 2 answers
A.DeploymentPreference property on the AWS::Serverless::Function resource.
B.AutoPublishAlias property on the AWS::Serverless::Function resource.
C.The function's CodeUri property pointing to the deployment package.
D.An event source mapping for the function.
E.The function's alias resource with a routing configuration.
AnswersA, B

The DeploymentPreference property on the AWS::Serverless::Function resource is fundamental for enabling canary deployments with AWS SAM. It integrates directly with AWS CodeDeploy to define the traffic shifting strategy, such as `Canary10Percent5Minutes`, which gradually routes a small percentage of traffic to the new function version. This property also configures automatic rollback mechanisms based on specified CloudWatch alarms, ensuring a safe and controlled deployment process.

Why this answer

Option A is correct because the DeploymentPreference property on the AWS::Serverless::Function resource is what tells SAM to perform a canary (or linear/all-at-once) deployment, specifying the deployment type, the alias, and the CloudWatch alarms that trigger rollback. Option B is correct because AutoPublishAlias is required for SAM to create and publish a Lambda alias (e.g., 'live') that the canary deployment shifts traffic to; without a published alias, DeploymentPreference cannot route weighted traffic between versions. Option C is not required for canary deployments since CodeUri simply specifies the function's code location and is unrelated to traffic shifting.

Option D is not required because an event source mapping only connects the function to a stream/queue and has nothing to do with canary traffic routing. Option E is not required because SAM automatically creates the alias and its routing configuration when AutoPublishAlias and DeploymentPreference are set, so the developer does not need to define an alias resource manually.

Exam trap

The trap here is that candidates often think manually defining a Lambda alias with routing configuration (Option E) is sufficient for canary deployments, but SAM requires both `AutoPublishAlias` (to automate version publishing and alias management) and `DeploymentPreference` (to integrate with CodeDeploy for traffic shifting) — the alias resource alone does not trigger CodeDeploy or enable automated canary rollouts.

137
Multi-Selectmedium

Which TWO actions should a developer take to minimize downtime when deploying a new version of a production application running on Amazon ECS with Fargate?

Select 2 answers
A.Delete the existing service and recreate it with the new task definition
B.Configure the ECS service to use a blue/green deployment with CodeDeploy
C.Update the target group health check settings to a more lenient threshold
D.Stop all running tasks and then start new tasks with the updated image
E.Update the ECS service with a new task definition and set minimum healthy percent to 100 and maximum percent to 200
AnswersB, E

Configuring the ECS service for blue/green deployment with AWS CodeDeploy is a robust strategy for minimizing downtime. CodeDeploy provisions an entirely new set of tasks (the "green" environment) running the updated application version alongside the existing "blue" environment. Once the new tasks pass health checks, CodeDeploy atomically shifts traffic from the old environment to the new one, ensuring users experience no interruption and providing an easy rollback mechanism if issues arise.

Why this answer

Blue/green deployments with AWS CodeDeploy allow you to create a new 'green' environment alongside the existing 'blue' environment, route traffic gradually, and instantly roll back if issues arise. This minimizes downtime by ensuring the old version remains fully available until the new version passes health checks and traffic is fully shifted.

Exam trap

The trap here is that candidates confuse 'rolling update' (which can also achieve zero downtime with proper settings) with the specific requirement for 'minimizing downtime' — the question expects you to recognize that blue/green deployments provide the most controlled and safe traffic shift, while the rolling update option (E) is a valid but less optimal choice for minimizing downtime in all scenarios.

138
Multi-Selecthard

Which THREE actions are required to set up a blue/green deployment for an Amazon ECS service using AWS CodeDeploy? (Choose three.)

Select 3 answers
A.Create a second ECS service for the green environment.
B.Create an ECS application and deployment group in CodeDeploy.
C.Create a new Application Load Balancer for the green environment.
D.Specify the task definition and container images in the AppSpec file.
E.Configure the ECS service to use the CodeDeploy deployment controller.
AnswersB, D, E

Establishing an ECS application and a deployment group within AWS CodeDeploy is a fundamental requirement. The CodeDeploy application acts as a logical container for deployments, while the deployment group specifies the target ECS service, the associated Application Load Balancer, and the listener configuration. This setup defines the specific deployment strategy, including how traffic will be shifted and any automated rollback triggers, making it essential for orchestrating the blue/green process.

Why this answer

CodeDeploy requires an ECS application and deployment group to manage the deployment lifecycle, including traffic shifting and rollback. The deployment group defines the ECS service, target groups, and load balancer listener for routing traffic between blue and green environments.

Exam trap

The trap here is that candidates mistakenly think they need to create a second ECS service or a new ALB for the green environment, but CodeDeploy handles the green infrastructure automatically within the same service and ALB.

139
MCQmedium

A developer needs different configuration values for dev, test, and prod in the same SAM template. Which feature is suitable?

A.Parameters and environment-specific parameter overrides
B.Hardcoded ARNs in every function
C.One AWS root account per environment
D.Disabling stack updates
AnswerA

This approach is highly effective for managing environment-specific configurations. By defining parameters in Infrastructure as Code (IaC) templates, such as AWS CloudFormation, developers can specify different values for resources like database endpoints, API keys, or instance types depending on the target environment (dev, test, production). Parameter overrides allow the same template to be deployed multiple times with distinct configurations, ensuring consistency in infrastructure definition while adapting to environmental needs.

Why this answer

AWS SAM supports Parameters and environment-specific parameter overrides, allowing you to define a single template and supply different configuration values (e.g., database URLs, API keys) for dev, test, and prod environments at deployment time. This is achieved by passing a JSON or YAML file with the `--parameter-overrides` flag in the `sam deploy` command, or by using the `parameters` section in a `samconfig.toml` file. This approach avoids duplicating templates and keeps infrastructure-as-code DRY and maintainable.

Exam trap

The trap here is that candidates may think hardcoding ARNs or using separate root accounts is simpler, but the exam tests knowledge of AWS-recommended patterns like parameter overrides and multi-account strategies using AWS Organizations, not root accounts.

How to eliminate wrong answers

Option B is wrong because hardcoding ARNs in every function violates the principle of environment isolation and requires manual changes for each environment, increasing the risk of misconfiguration and deployment errors. Option C is wrong because using one AWS root account per environment is an anti-pattern; it introduces unnecessary administrative overhead, security risks, and violates the AWS Well-Architected Framework's recommendation to use separate AWS accounts (not root accounts) for environment isolation. Option D is wrong because disabling stack updates prevents any future changes to the stack, making it impossible to update configuration values or deploy new features, which is impractical for ongoing development and deployment.

140
MCQmedium

A company uses AWS CodeDeploy to deploy a web application to an Auto Scaling group. The deployment fails during the BeforeInstall lifecycle event. What should the developer do to troubleshoot the issue?

A.Check the deployment group configuration.
B.Verify the build output from CodeBuild.
C.Check the appspec.yml file for errors in the BeforeInstall hook.
D.Review the deployment configuration settings.
AnswerC

The BeforeInstall hook is defined in the appspec.yml file under the hooks section, so a malformed YAML, an incorrect hook name, a missing script path, or a script without the execute permission will cause CodeDeploy to fail at that stage. You need to inspect the appspec.yml and the script it references to identify the exact error, because lifecycle hooks are entirely driven by that file, not by the deployment group or deployment configuration.

Why this answer

The BeforeInstall hook scripts are defined in the appspec.yml file, and a failure during that lifecycle event typically indicates an error in the script or the hook configuration. Option A is wrong because the deployment group configuration (e.g., Auto Scaling group, tags) does not directly cause a script failure in the BeforeInstall hook. Option B is wrong because the build output from CodeBuild is already successful and not related to the deployment failure.

Option D is wrong because deployment configuration settings (e.g., deployment type, rollback triggers) do not affect the execution of the BeforeInstall hook scripts.

Exam trap

A common trap is to overlook the appspec.yml file and instead check deployment group or configuration settings when the issue is clearly with the script specified in the appspec hooks.

141
MCQhard

A developer is deploying a serverless application using the AWS Serverless Application Model (SAM). The application consists of several Lambda functions and an API Gateway. The developer wants to enable gradual deployment of Lambda function versions with automatic rollback based on CloudWatch alarms. What should the developer add to the SAM template?

A.Use 'AWS::Lambda::Version' and 'AWS::Lambda::Alias' resources to manually shift traffic and set up CloudWatch alarms to revert the alias if needed.
B.Add a 'DeploymentPreference' property with 'Type' set to 'Linear' and specify a 'Alarms' list for rollback.
C.Add 'AutoPublishAlias' and 'DeploymentPreference' properties to the Lambda function resource, specifying a canary deployment with a CloudWatch alarm for rollback.
D.Add a 'CodeDeployLambdaAlias' resource to the template and configure the deployment group with a canary deployment configuration.
AnswerC

This is the correct approach for implementing automated canary deployments with rollback in SAM. The 'AutoPublishAlias' property on an 'AWS::Serverless::Function' resource automatically creates a new Lambda version and updates an alias to point to it, enabling traffic shifting. Coupled with 'DeploymentPreference', SAM integrates with AWS CodeDeploy to manage the gradual traffic shift (e.g., canary) and automatically rolls back to the previous stable version if specified CloudWatch alarms are breached during the deployment.

Why this answer

The correct answer is C because AWS SAM natively supports gradual deployments through the `AutoPublishAlias` and `DeploymentPreference` properties on the `AWS::Serverless::Function` resource. `AutoPublishAlias` automatically creates a new Lambda version and an alias pointing to it whenever the function code changes. `DeploymentPreference` then instructs SAM to use AWS CodeDeploy to shift traffic to the new version according to a specified strategy (e.g., Canary, Linear, AllAtOnce) and to automatically roll back if any specified CloudWatch alarms trigger. This is the standard, declarative way to enable safe deployments in SAM.

Exam trap

DVA-C02 often tests the misconception that you need to manually create Lambda versions and aliases or use CodeDeploy resources directly, when in fact SAM's `AutoPublishAlias` and `DeploymentPreference` properties handle this automatically.

How to eliminate wrong answers

Option A is wrong because manually creating `AWS::Lambda::Version` and `AWS::Lambda::Alias` resources does not provide automatic traffic shifting or rollback; it requires custom logic and does not integrate with CodeDeploy for gradual deployments. Option B is wrong because `DeploymentPreference` is not a standalone property; it must be used in conjunction with `AutoPublishAlias` on the Lambda function resource, and the `Alarms` list must be specified within `DeploymentPreference`, not separately. Option D is wrong because `CodeDeployLambdaAlias` is not a valid SAM resource type; SAM abstracts the CodeDeploy configuration through the `DeploymentPreference` property, and manually adding a CodeDeploy resource is unnecessary and not supported in SAM templates.

142
MCQmedium

A company uses AWS CodeBuild to run tests and build artifacts for a Java application. The build process is taking longer than expected. The developer wants to speed up the build by caching dependencies. What should the developer do?

A.Use a CodeCommit repository to store dependencies.
B.Store dependencies in an S3 bucket and download them in each build.
C.Enable local caching in the CodeBuild project configuration.
D.Mount an Amazon EFS file system to the build environment and store dependencies there.
AnswerC

Enabling local caching in the CodeBuild project configuration is the most effective and direct solution for significantly speeding up build times by reusing previously downloaded dependencies. CodeBuild offers various local caching options, including caching artifacts in the build host's Docker layer or a specified local directory, or even using an S3 bucket for more persistent, shared caching. This mechanism ensures that common dependencies are stored and quickly retrieved for subsequent builds, drastically reducing network I/O, package installation times, and overall build execution duration.

Why this answer

CodeBuild's local caching feature allows the build environment to cache dependencies (e.g., Maven local repository) in a local directory that persists across build runs for the same project. This eliminates the need to re-download dependencies on every build, significantly reducing build time. The cache is stored on the build instance's local storage and is automatically managed by CodeBuild.

Exam trap

The trap here is that candidates often assume external storage (S3 or EFS) is required for caching, but CodeBuild's built-in local caching is specifically designed for this purpose and avoids the latency of network-based storage.

How to eliminate wrong answers

Option A is wrong because CodeCommit is a Git-based source control service, not a dependency cache; storing dependencies there would require manual management and does not integrate with CodeBuild's caching mechanism. Option B is wrong because downloading dependencies from S3 in each build still incurs network latency and download time, negating the performance benefit of caching. Option D is wrong because mounting an EFS file system adds network filesystem overhead and latency, and EFS is designed for shared file storage across multiple instances, not for low-latency build caching within a single build environment.

143
MCQmedium

A company uses AWS CodeDeploy to deploy a web application to an Auto Scaling group. The deployment fails with the error 'The overall deployment failed because too many individual instances failed deployment, too few healthy instances are available for deployment, or some instances in your deployment group are experiencing problems.' The deployment group has a minimum of 2 instances and a maximum of 4. The deployment configuration is CodeDeployDefault.OneAtATime. What is the most likely cause of the failure?

A.The deployment group's maximum instances is set to 4, which exceeds the number of instances in the Auto Scaling group.
B.The Auto Scaling group has only 2 instances, and one instance fails during deployment, leaving less than the required healthy instances.
C.The IAM role attached to the instances does not have sufficient permissions to download the revision from Amazon S3.
D.The revision is not properly zipped or the AppSpec file is missing.
AnswerB

This scenario directly addresses a common CodeDeploy failure mode when using conservative deployment strategies like CodeDeployDefault.OneAtATime on small Auto Scaling groups. If the Auto Scaling group has only two instances, and one instance fails its health checks or application startup during the deployment, the number of healthy instances immediately drops to one. If the deployment configuration's MinimumHealthyHosts threshold requires more than one healthy instance (e.g., 50% of 2 instances, which rounds up to 1, but if the next step requires taking another instance out of service, it would fail), or if the deployment is configured to halt if any instance fails, the deployment will stop due to insufficient healthy hosts, preventing further degradation.

Why this answer

The deployment configuration CodeDeployDefault.OneAtATime deploys to one instance at a time, and the deployment group has a minimum of 2 healthy instances. If one instance fails during deployment, only 1 healthy instance remains, which is below the minimum required threshold of 2. This causes CodeDeploy to stop the deployment and mark it as failed, as it cannot maintain the required number of healthy instances.

Exam trap

The trap here is that candidates may overlook the interaction between the deployment configuration (OneAtATime) and the minimum healthy instances setting, assuming any instance failure is due to a code or permission issue rather than a capacity constraint.

How to eliminate wrong answers

Option A is wrong because the maximum instances setting of 4 does not cause a deployment failure; it only limits the number of instances that can be deployed to at once, and the Auto Scaling group can have fewer instances than the maximum. Option B is correct as explained. Option C is wrong because insufficient IAM permissions would cause a specific error related to S3 access, not the generic 'too few healthy instances' error.

Option D is wrong because a malformed revision or missing AppSpec file would result in a different error, such as 'ScriptFailed' or 'InvalidRevision', not the healthy instances error.

144
MCQeasy

A developer needs to deploy a new version of a Lambda function that uses environment variables for database credentials. Which AWS service should be used to securely store and retrieve the credentials?

A.Amazon DynamoDB with encryption at rest
B.Amazon S3 with server-side encryption
C.AWS Systems Manager Parameter Store
D.AWS Secrets Manager
AnswerD

AWS Secrets Manager is purpose-built for securely storing, managing, and automatically rotating various types of secrets, including database credentials, API keys, and other sensitive information. It integrates seamlessly with AWS services like Lambda for automated rotation, ensuring secrets are regularly updated without manual intervention, significantly enhancing security posture. Furthermore, it provides robust auditing, fine-grained access control via IAM, and easy retrieval through an API, making it the ideal solution for managing secrets at scale.

Why this answer

AWS Secrets Manager is the best choice because it is designed specifically for securely storing secrets like database credentials and offers automatic rotation. Option C (AWS Systems Manager Parameter Store) can store secrets but lacks automatic rotation and is not as feature-rich for secret management. Option A (DynamoDB) and Option B (S3) are not intended for secret storage and lack native secret management capabilities such as rotation and fine-grained access control for secrets.

145
MCQeasy

A developer is using AWS Elastic Beanstalk to deploy a web application. The developer needs to update the environment's configuration to use a larger instance type. What is the most efficient way to apply this change with minimal downtime?

A.Update the environment configuration through the Elastic Beanstalk console or CLI, and use a rolling update strategy to apply the change to instances in batches.
B.Perform a blue/green deployment by creating a new environment with the larger instance type, then swap the environment URLs.
C.Modify the Auto Scaling group launch configuration directly to use the larger instance type, then manually terminate each instance.
D.Terminate the current environment and create a new one with the larger instance type.
AnswerA

This is the recommended and most efficient method for updating configuration parameters like instance types. Elastic Beanstalk manages the underlying infrastructure, and a rolling update strategy ensures that instances are replaced in batches, maintaining application availability throughout the process. The environment remains operational, serving traffic from the healthy instances while others are updated.

Why this answer

Elastic Beanstalk supports rolling updates, which allow you to change the instance type by updating instances in batches, minimizing downtime. Options B, C, and D are incorrect: B involves blue/green deployment, which is more complex and not the most efficient for a simple configuration change; C is wrong because directly modifying the Auto Scaling group launch configuration may be overwritten by Elastic Beanstalk and does not leverage Elastic Beanstalk's managed rolling update; D causes full downtime by terminating and recreating the environment.

146
MCQhard

A developer is troubleshooting a deployment failure in AWS CodePipeline. The deploy stage uses the above IAM policy for the service role. The pipeline fails when trying to update the Elastic Beanstalk environment. What is the most likely cause?

A.The policy restricts the UpdateEnvironment action to a specific environment ARN, but the pipeline is updating a different environment.
B.The policy does not allow DescribeEnvironmentResources, which is required for the deployment.
C.The policy denies all actions on the environment, preventing the update.
D.The policy denies DeleteEnvironment, which is required for the update.
AnswerA

When an IAM policy scopes elasticbeanstalk:UpdateEnvironment to a specific environment ARN in its Resource element, any UpdateEnvironment call targeting a different environment ARN is evaluated against no matching Allow statement and is implicitly denied, which precisely matches a pipeline that fails only when updating an environment other than the one named in the policy.

Why this answer

The most likely cause is option A: the policy restricts the UpdateEnvironment action to a specific environment ARN, but the pipeline is updating a different environment. In Elastic Beanstalk, elasticbeanstalk:UpdateEnvironment must be allowed on the exact environment ARN being updated; if the Resource element names a different environment, the API call is denied and the deploy stage fails. Option B is not the issue because DescribeEnvironmentResources is a read-only action and is not required to perform the environment update.

Option C is too broad and inaccurate, since the policy does not deny all actions on the environment. Option D is also incorrect because DeleteEnvironment is not needed to update an existing Elastic Beanstalk environment.

147
MCQeasy

A developer is using AWS CloudFormation to deploy a stack that includes an Amazon S3 bucket with a bucket policy that grants public read access. The stack creation fails with the error 'Access Denied for bucket: bucket-policy does not allow access.' The developer has full administrative permissions in AWS. The developer verifies that the bucket policy is correctly formatted. What is the most likely cause of the failure?

A.The developer does not have permissions to create S3 buckets.
B.The S3 bucket name is already in use by another account.
C.The S3 Block Public Access settings are enabled at the account level, preventing the bucket policy from granting public access.
D.The S3 bucket is encrypted with AWS KMS, and the bucket policy does not include kms:Decrypt permissions.
AnswerC

This is the correct explanation. AWS S3 Block Public Access (BPA) settings, when enabled at the account level, override any bucket policies that attempt to grant public read or write access to S3 buckets or objects. If a CloudFormation template attempts to deploy an S3 bucket with a bucket policy that grants public access, and account-level BPA is active, the policy application will fail because the BPA settings take precedence, effectively blocking the public access grant and causing the stack creation to roll back.

Why this answer

AWS S3 Block Public Access settings (at the account or bucket level) prevent the creation of public bucket policies. When CloudFormation attempts to apply a public bucket policy while Block Public Access is enabled, S3 rejects the PutBucketPolicy API call with an 'Access Denied' error. Since the developer has full administrative permissions, the failure is not due to missing IAM permissions but rather S3 Block Public Access blocking the public policy.

Exam trap

Candidates often assume that having full AdministratorAccess IAM permissions bypasses all restrictions. However, S3 Block Public Access acts as a guardrail that overrides IAM permissions, causing the PutBucketPolicy API call to fail with Access Denied even for administrators.

How to eliminate wrong answers

Option A is wrong because the developer has full administrative permissions in AWS, which includes the ability to create S3 buckets, so the failure is not due to insufficient permissions. Option B is wrong because if the bucket name were already in use by another account, the error would be 'BucketAlreadyExists' or 'BucketAlreadyOwnedByYou', not 'Access Denied for bucket: bucket-policy does not allow access'. Option D is wrong because KMS encryption does not affect bucket policy evaluation; the error is about access control for the bucket policy itself, not about decrypt permissions, and the bucket policy does not need kms:Decrypt permissions to be applied.

148
MCQmedium

A developer created a CloudFormation template to host a static website. After deployment, the website returns 403 Forbidden errors. What is the most likely cause?

A.The bucket has versioning enabled, which blocks public access.
B.The bucket name is not unique.
C.The bucket policy does not allow public access.
D.The bucket does not have static website hosting enabled.
AnswerC

The bucket policy explicitly includes 'Principal: "*"', which is the standard declaration for granting public access to an S3 bucket. This principal allows any user, authenticated or unauthenticated, to perform the specified actions on the bucket's objects, assuming no other conflicting policies or S3 Block Public Access settings override it. Therefore, the bucket policy itself is configured to permit public access, making this option incorrect as the reason for access failure.

Why this answer

An 'Access Denied' (403 Forbidden) error on an Amazon S3 static website endpoint indicates that the requester does not have permission to access the resource. By default, all new S3 buckets and objects are private. To allow public access to the website's assets, you must add a bucket policy that grants public read permissions (`s3:GetObject`) to anonymous users, and ensure that S3 Block Public Access settings are disabled.

If static website hosting were not enabled, the website endpoint would not return a 403 Forbidden error; it would not resolve or would return a 404 error. Therefore, the missing bucket policy is the most likely cause.

Exam trap

Candidates often confuse the causes of 403 Forbidden and 404 Not Found errors on S3. A 403 Forbidden error on a website endpoint points to a permissions issue (such as a missing bucket policy or active Block Public Access settings). If static website hosting were not enabled, the website endpoint would not resolve or function at all, rather than returning a 403 Forbidden error.

How to eliminate wrong answers

Option A is wrong because enabling versioning does not affect public access; versioning is a separate feature for preserving object versions and does not block public access. Option B is wrong because a non-unique bucket name would cause a deployment failure (BucketAlreadyExists error), not a 403 Forbidden after successful deployment. Option C is wrong because the bucket policy may allow public access, but without static website hosting enabled, the website endpoint is not active, and requests to the REST endpoint (even with a public policy) can still return 403 if the bucket is not configured for website hosting or if the policy does not explicitly grant s3:GetObject to the website endpoint's principal.

149
Multi-Selecteasy

A developer is deploying a serverless application using the AWS Serverless Application Model (SAM). The application includes an Amazon DynamoDB table and a Lambda function that reads from the table. The developer wants to define the DynamoDB table and the Lambda function in the SAM template. Which THREE resource types should the developer include in the template? (Choose THREE.)

Select 3 answers
A.AWS::DynamoDB::Table
B.AWS::Lambda::Function
C.AWS::Serverless::DynamoDB
D.AWS::Serverless::SimpleTable
E.AWS::Serverless::Function
AnswersA, D, E

AWS::DynamoDB::Table is a native CloudFormation resource that can be embedded directly in a SAM template. It gives you full control over DynamoDB settings such as key schema, billing mode, global secondary indexes, and stream specification, whereas SAM's Serverless::SimpleTable only exposes a subset of these properties. Using this resource is appropriate when you need advanced configuration, like TTL or point-in-time recovery, without leaving the template.

Why this answer

The correct options are A (AWS::DynamoDB::Table), D (AWS::Serverless::SimpleTable), and E (AWS::Serverless::Function). In an AWS SAM template, you can define a DynamoDB table using either the standard CloudFormation resource AWS::DynamoDB::Table (for full control) or the SAM shorthand AWS::Serverless::SimpleTable (for simpler use cases). For a Lambda function, the recommended SAM resource is AWS::Serverless::Function, which provides additional SAM features like event mappings and policies.

Option B (AWS::Lambda::Function) is a CloudFormation resource that could be used but is not the typical SAM choice; the question asks for resource types to include in a SAM template, so the serverless type is expected. Option C (AWS::Serverless::DynamoDB) is not a valid AWS resource type.

150
MCQeasy

A startup is deploying a Node.js application using AWS Elastic Beanstalk. They have configured the environment to use a load-balanced, auto-scaled environment with a minimum of 2 instances and a maximum of 4. The application connects to an Amazon RDS MySQL database. After a successful deployment, users report that the application is intermittently returning errors. The developer checks the Elastic Beanstalk logs and finds that the application is timing out when connecting to the database. The developer also notices that the database connection string is hardcoded in the application code. What is the most likely cause of the intermittent errors?

A.The security group for the RDS instance does not allow inbound traffic from the Elastic Beanstalk environment's security group.
B.The RDS instance has reached its maximum number of concurrent connections because the application instances are not using connection pooling.
C.The application code has a bug that causes the database connection to be closed prematurely.
D.The RDS instance is not configured for Multi-AZ deployment, causing failover issues.
AnswerB

Node.js applications, especially when deployed across multiple Elastic Beanstalk instances, can quickly exhaust the RDS instance's maximum concurrent connection limit if they establish a new database connection for every request without proper pooling. Each application instance, without pooling, might open numerous persistent connections, leading to connection starvation for subsequent requests and manifesting as intermittent timeouts or failures when the limit is reached. Connection pooling reuses existing connections, significantly reducing the total number of open connections to the database.

Why this answer

The correct answer is B: the RDS instance has reached its maximum number of concurrent connections because the application instances are not using connection pooling. In a load-balanced, auto-scaled Elastic Beanstalk environment with 2-4 Node.js instances, each instance opens its own database connections, and without connection pooling or Amazon RDS Proxy, the total can exceed the MySQL max_connections limit, producing intermittent connection timeouts under load. Option A is unlikely because a security group misconfiguration would typically cause consistent, not intermittent, connection failures across all instances.

Option C is not supported by the symptom of timeouts when connecting, which points to connection exhaustion rather than premature closure. Option D is irrelevant because lack of Multi-AZ affects availability during an AZ failure, not routine intermittent connection timeouts.

← PreviousPage 2 of 4 · 254 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Deployment questions.

CCNA Deployment Questions — Page 2 of 4 | Courseiva