Courseiva

CCNA Security Questions

75 of 314 questions · Page 3/5 · Security · Answers revealed

151
MCQmedium

A developer is building a serverless application using an API Gateway HTTP API and Lambda. The developer needs to authenticate users with a JWT token. Which API Gateway feature should be used?

A.Lambda Authorizer
B.IAM Authorizer
C.JWT Authorizer
D.Amazon Cognito User Pools
AnswerC

An API Gateway JWT authorizer (also known as a native OIDC/OAuth 2.0 authorizer) is specifically designed to validate JSON Web Tokens (JWTs) issued by a third-party OpenID Connect (OIDC) or OAuth 2.0 compliant identity provider. It declaratively configures the issuer URL and audience, allowing API Gateway to automatically fetch public keys, verify the token's signature, expiration, and claims without custom code. This makes it the most direct and efficient solution for authenticating existing JWTs.

Why this answer

API Gateway HTTP APIs support JWT Authorizers natively. This feature allows API Gateway to validate JSON Web Tokens (JWTs) directly without invoking a Lambda function, verifying the token's signature, expiry, and issuer against a configured identity provider (such as Amazon Cognito or any OIDC-compliant provider). This is the most efficient and cost-effective way to handle JWT authentication in HTTP APIs.

Exam trap

The trap is that candidates often assume they need a custom Lambda Authorizer to validate JWTs, or confuse REST API authorizers with HTTP API authorizers. For HTTP APIs, a native JWT Authorizer should be used instead of a custom Lambda Authorizer to reduce latency and cost.

How to eliminate wrong answers

Option A is wrong because a Lambda Authorizer (formerly Custom Authorizer) is used when you need custom validation logic beyond simple JWT verification, such as calling an external identity provider or performing complex claims mapping; it introduces unnecessary latency and cost for straightforward JWT validation. Option B is wrong because IAM Authorizer uses AWS Signature Version 4 (SigV4) for request signing and is intended for AWS service-to-service or IAM user authentication, not for validating externally-issued JWTs. Option D is wrong because Amazon Cognito User Pools is a full identity provider that issues JWTs, but it is not an API Gateway authorizer feature; you would still need to use a JWT Authorizer or Lambda Authorizer to validate those tokens in API Gateway.

152
MCQhard

A company requires that all API calls to create an Amazon S3 bucket must include a specific tag (e.g., 'CostCenter'). Which IAM policy condition key should a developer use to enforce this requirement?

A.aws:RequestTag
B.aws:ResourceTag
C.s3:ExistingObjectTag
D.aws:TagKeys
AnswerA

This condition key checks tags that are included in the API request. You can require a specific tag key and value to be present on the CreateBucket request, ensuring that all buckets are tagged at creation.

Why this answer

The `aws:RequestTag` condition key evaluates the tags that are included in the API request itself. When a developer attempts to create an S3 bucket, the IAM policy can use `aws:RequestTag` to require that a specific tag key (e.g., 'CostCenter') is present in the `CreateBucket` request. This ensures that the tag is applied at creation time, enforcing the company's tagging requirement.

Exam trap

The trap here is that candidates confuse `aws:RequestTag` (tags in the request) with `aws:ResourceTag` (tags on an existing resource), leading them to choose the wrong condition key for enforcing tagging at resource creation.

How to eliminate wrong answers

Option B is wrong because `aws:ResourceTag` evaluates the tags already attached to an existing resource, not the tags in the creation request, so it cannot enforce tagging at bucket creation. Option C is wrong because `s3:ExistingObjectTag` is used to conditionally allow actions based on tags on existing objects within a bucket, not on the bucket creation request itself. Option D is wrong because `aws:TagKeys` is used to restrict which tag keys can be used in a request, but it does not require that a specific tag key be present; it only controls the allowed set of keys.

153
MCQmedium

A company is using AWS Key Management Service (KMS) to encrypt data in S3. The security team wants to ensure that only the company's AWS account can access the KMS key. What should be done?

A.Disable the KMS key and re-enable it only when needed.
B.Modify the key policy to remove any statements that allow access from external AWS accounts.
C.Use an S3 bucket policy to deny access to any user not from the company's account.
D.Attach an IAM policy to the key that denies access to external accounts.
AnswerB

KMS key policies are the definitive and mandatory access control mechanism for every AWS KMS key, dictating precisely which IAM identities and AWS accounts can perform cryptographic operations. By meticulously reviewing the key policy and removing any specific `Statement` blocks that grant `kms:*` or targeted permissions like `kms:Decrypt` or `kms:GenerateDataKey` to external AWS account IDs or cross-account IAM roles, the company can precisely revoke unauthorized access without impacting legitimate internal usage. This is the most granular and secure method to manage KMS key access.

Why this answer

Modifying the key policy to remove any statements that allow access from external AWS accounts ensures that only the company's AWS account can use the KMS key. The key policy explicitly defines who can access the key, and removing external account access restricts it to the key owner's account. Option A is incorrect because disabling the key prevents all use, not just external access.

Option C is incorrect because an S3 bucket policy cannot control access to the KMS key itself; it only governs S3 operations. Option D is incorrect because IAM policies can grant or deny access, but the key policy must also allow the account; however, the key policy already allows the account's IAM users by default if they have the right permissions, but the requirement is to ensure only the company's account can access, which is achieved by removing external account access from the key policy.

154
MCQhard

An API Gateway HTTP API should allow access only to users authenticated by an external OIDC provider. Which authorizer type is most appropriate?

A.IAM authorizer
B.API key authorizer
C.JWT authorizer configured for the issuer and audience
D.S3 bucket policy
AnswerC

A JWT authorizer for an HTTP API validates JSON Web Tokens (JWTs) presented by clients, ensuring they are signed by a trusted issuer and intended for the specific API. By configuring the issuer (iss) and audience (aud) claims, the authorizer cryptographically verifies the token's authenticity and its intended recipient. This mechanism precisely controls access by allowing only requests with valid, unexpired tokens from a recognized identity provider, making it ideal for OAuth 2.0 and OpenID Connect flows.

Why this answer

An HTTP API Gateway with an external OIDC provider requires a JWT authorizer. The JWT authorizer validates the token's signature, issuer, and audience against the OIDC provider's configuration, ensuring only authenticated users gain access. This is the native AWS mechanism for integrating third-party OIDC identity providers like Auth0 or Okta.

Exam trap

The trap here is that candidates confuse the JWT authorizer with the Lambda authorizer, thinking a custom Lambda is always required for OIDC, but the JWT authorizer natively supports OIDC without custom code when the provider issues standard JWTs.

How to eliminate wrong answers

Option A is wrong because an IAM authorizer uses AWS Signature Version 4 for signing requests with IAM credentials, not OIDC tokens, and is designed for AWS-authenticated principals, not external identity providers. Option B is wrong because an API key authorizer only validates a static key passed in the header, which provides no authentication of the user's identity and cannot verify OIDC tokens. Option D is wrong because an S3 bucket policy controls access to S3 resources, not API Gateway endpoints, and has no mechanism to validate OIDC tokens.

155
MCQmedium

A developer is building a REST API with Amazon API Gateway and needs to authorize requests based on a custom JSON Web Token (JWT) that includes claims for user roles. Which authorization mechanism should the developer use?

A.Lambda authorizer
B.IAM authorizer
C.Amazon Cognito user pools authorizer
D.API Gateway resource policy
AnswerA

A Lambda authorizer, formerly known as a custom authorizer, is an AWS Lambda function that API Gateway invokes before forwarding the request to the backend integration. It receives the incoming custom JWT token, validates it against custom logic (e.g., verifying signature, issuer, audience, and expiration), and then returns an IAM policy document. This policy dictates whether the principal is authorized to access the requested API Gateway method, providing ultimate flexibility for any token type.

Why this answer

A Lambda authorizer (formerly known as a custom authorizer) is the correct choice because it allows the developer to validate a custom JWT and extract claims such as user roles directly within the Lambda function. This enables fine-grained authorization logic that can inspect the JWT payload, verify its signature using a custom or third-party key, and return an IAM policy based on the claims, which API Gateway then enforces for the incoming request.

Exam trap

The trap here is that candidates often confuse a Lambda authorizer with a Cognito user pools authorizer, assuming any JWT can be validated by Cognito, but Cognito only accepts tokens it issued, not custom JWTs from other providers.

How to eliminate wrong answers

Option B is wrong because an IAM authorizer uses AWS Signature Version 4 to sign requests with IAM credentials, not a custom JWT; it cannot inspect or validate JWT claims like user roles. Option C is wrong because Amazon Cognito user pools authorizer only works with JWTs issued by a Cognito user pool, not with a custom JWT from an external identity provider or self-issued token. Option D is wrong because an API Gateway resource policy controls access at the account or VPC level based on source IP, VPC endpoint, or AWS account, not on individual request-level JWT claims or user roles.

156
MCQeasy

A developer needs to allow an IAM user to perform only specific actions on an S3 bucket. Which type of policy should be attached to the IAM user?

A.A service control policy
B.A bucket policy
C.A trust policy
D.An IAM policy
AnswerD

An IAM policy is a JSON document that explicitly defines permissions, specifying what actions are allowed or denied on which AWS resources, and under what conditions. These policies are directly attached to IAM identities such as users, groups, or roles, making them the fundamental mechanism for granting specific permissions to an IAM user. By attaching a tailored IAM policy to a user, a developer can precisely control and limit the actions that user is authorized to perform across AWS services.

Why this answer

An IAM policy (Option D) is the correct choice because it is an identity-based policy that can be directly attached to an IAM user, group, or role to grant or deny permissions for specific actions on AWS resources, including S3 buckets. This allows the developer to precisely control which S3 actions (e.g., s3:GetObject, s3:PutObject) the user can perform on a particular bucket, meeting the requirement of limiting the user to specific actions.

Exam trap

AWS often tests the distinction between identity-based policies (IAM policies) and resource-based policies (bucket policies), where candidates mistakenly choose a bucket policy thinking it can control user permissions directly, but bucket policies are tied to the resource, not the user identity.

How to eliminate wrong answers

Option A is wrong because a service control policy (SCP) is used in AWS Organizations to set permission boundaries for all accounts in an organization, not to grant permissions to individual IAM users. Option B is wrong because a bucket policy is a resource-based policy attached directly to an S3 bucket, not to an IAM user; while it can grant cross-account access, it does not control permissions for a specific IAM user within the same account. Option C is wrong because a trust policy is attached to an IAM role to define which principals (e.g., users, services) can assume that role, not to grant direct permissions for S3 actions to an IAM user.

157
MCQeasy

A developer runs a CloudTrail lookup command and sees a CreateKey event. What does this event represent?

A.An existing KMS key was rotated.
B.A new database encryption key was created.
C.A new KMS customer master key was created.
D.A new service-linked key was created.
AnswerC

This option is correct because the `CreateKey` API is the fundamental operation in AWS Key Management Service (KMS) used to provision a new Customer Master Key (CMK). A CMK is the primary resource you manage in KMS for cryptographic operations. Therefore, a CloudTrail lookup showing a `CreateKey` event precisely indicates that a new, unique KMS customer master key has been successfully generated and made available within the AWS account.

Why this answer

The `CreateKey` event in AWS CloudTrail indicates that a new KMS customer master key (CMK) was created. This is the only operation that generates a `CreateKey` event; key rotation, database encryption key creation, and service-linked key creation use different API calls (e.g., `RotateKey`, `CreateGrant`, or `CreateKey` with a different service principal).

Exam trap

The trap here is that candidates assume `CreateKey` only applies to CMKs, but AWS services also use this API for service-linked keys; however, the exam expects you to recognize that the event name is generic and the context (e.g., `userIdentity` or `requestParameters`) determines the key type.

How to eliminate wrong answers

Option A is wrong because key rotation is performed via the `RotateKey` API or automatic rotation settings, not `CreateKey`. Option B is wrong because database encryption keys are typically managed by the database service (e.g., RDS, DynamoDB) using KMS grants or direct CMK usage, not a standalone `CreateKey` event. Option D is wrong because service-linked keys are created by AWS services on your behalf using a different API call (e.g., `CreateKey` with a service principal), but the event name is still `CreateKey`; however, the question's context implies a standard CMK creation, and service-linked keys are a specific subset that would be logged with a different `requestParameters` (e.g., `KeyUsage` and `Origin`).

158
MCQeasy

A developer needs to allow an EC2 instance to access an S3 bucket without storing credentials on the instance. Which approach is the most secure?

A.Create an IAM user with access keys and store them on the instance.
B.Use S3 bucket policy to allow the EC2 instance's public IP.
C.Store the access keys in Systems Manager Parameter Store and retrieve at runtime.
D.Use an IAM role for EC2 with a policy granting S3 access.
AnswerD

An IAM role attached to the instance delivers temporary credentials through the instance metadata service, rotated automatically by AWS. No long-term access keys are stored on disk or in code, eliminating the credential-exposure risk the stem prohibits.

Why this answer

An IAM role attached to an EC2 instance delivers temporary, automatically rotated credentials via the Instance Metadata Service (IMDS), so no long-lived secrets ever touch the instance filesystem. The role's trust policy allows ec2.amazonaws.com to assume it, and the attached permissions policy scopes exactly which S3 actions and resources are allowed. This is AWS's recommended pattern for granting AWS service access to compute resources.

Exam trap

DVA-C02 often tests the misconception that storing credentials in Parameter Store or Secrets Manager is equivalent to using an IAM role — both still involve static secrets, whereas roles provide short-lived, auto-rotated credentials.

How to eliminate wrong answers

Option A is wrong because embedding IAM user access keys on an instance creates long-lived static credentials that can be exfiltrated from disk or environment variables and must be manually rotated. Option B is wrong because S3 bucket policies cannot authenticate by source public IP for an EC2 instance reliably — the instance's public IP is dynamic (changes on stop/start), and IP-based conditions do not provide identity-based authorization. Option C is wrong because Parameter Store still stores static IAM user credentials that must be retrieved and held in memory by the application, so the secret still exists and can leak; it only moves the storage location, not the underlying risk.

159
Multi-Selectmedium

A company needs to store application secrets such as database passwords and API keys. The secrets must be automatically rotated every 30 days. Which THREE AWS services or features can be used together to meet this requirement? (Choose THREE.)

Select 3 answers
A.AWS Lambda to implement the rotation function
B.AWS CloudHSM
C.AWS Systems Manager Parameter Store
D.AWS Secrets Manager
E.AWS KMS to encrypt the secrets
AnswersA, D, E

AWS Lambda functions are essential for implementing the automatic rotation of secrets managed by AWS Secrets Manager. Secrets Manager invokes a pre-configured Lambda function on a scheduled basis to programmatically change the credentials in the target database or service. This function handles the logic for creating new credentials, updating the secret in Secrets Manager, and then deprecating the old credentials, ensuring secure and automated secret lifecycle management without manual intervention.

Why this answer

AWS Lambda is correct because it can be used as a custom rotation function for AWS Secrets Manager. Secrets Manager natively supports automatic rotation using a Lambda function that updates the secret value in both the service and the database or third-party service. This allows the company to meet the 30-day rotation requirement by scheduling the Lambda function via a CloudWatch Events rule or Secrets Manager's built-in rotation schedule.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store with Secrets Manager, but Parameter Store lacks native automatic rotation, making it unsuitable for this requirement without additional custom infrastructure.

160
MCQeasy

A developer needs to securely pass a secret API key to an AWS Lambda function. What is the MOST secure and recommended approach?

A.Store the API key in an Amazon DynamoDB table and query it from the Lambda function.
B.Hardcode the API key in the Lambda function code.
C.Store the API key in an environment variable of the Lambda function.
D.Store the API key in AWS Secrets Manager and retrieve it in the Lambda function code.
AnswerD

AWS Secrets Manager is the recommended and most secure service for storing and managing sensitive data like API keys. It encrypts secrets at rest and in transit, provides robust automatic rotation capabilities, and integrates seamlessly with AWS Lambda for secure retrieval via the AWS SDK. This approach ensures the API key is never exposed in plain text within the application code or configuration, adhering to security best practices and simplifying secret lifecycle management and auditing.

Why this answer

AWS Secrets Manager is a dedicated service for securely storing and managing secrets like API keys. It integrates natively with Lambda, allowing retrieval at runtime with minimal permissions using IAM roles. Option A (DynamoDB) is less secure because it requires managing encryption and access policies manually, and the secret might be exposed in query logs.

Option B (hardcoding) is insecure as the key is visible in source code and version control. Option C (environment variables) can be viewed in the Lambda console and CloudWatch Logs, and they are not encrypted by default unless using encryption helpers. Therefore, Secrets Manager (Option D) is the most secure and recommended approach.

161
MCQeasy

A developer needs to allow an EC2 instance to access a DynamoDB table. Which IAM entity should be attached to the EC2 instance?

A.IAM group
B.IAM role
C.IAM user
D.Resource-based policy on the DynamoDB table
AnswerB

An IAM role is an identity that can assume permissions, designed for AWS services, federated users, or EC2 instances. When an IAM role is attached to an EC2 instance via an instance profile, the instance can assume the role, obtaining temporary security credentials that grant it the permissions defined in the role's policies. This mechanism allows the EC2 instance to securely access other AWS services like DynamoDB without storing long-term credentials on the instance itself, adhering to the principle of least privilege and enhancing security.

Why this answer

An IAM role is the correct entity to attach to an EC2 instance because it provides temporary security credentials via the AWS Security Token Service (STS) that the instance can assume. This allows the EC2 instance to securely access the DynamoDB table without embedding long-term access keys in the instance. The role is attached to the instance profile, which the EC2 instance metadata service (IMDS) uses to retrieve credentials automatically.

Exam trap

The trap here is that candidates often confuse IAM roles with IAM users, thinking a user can be attached to an EC2 instance, but AWS does not allow attaching a user to a resource—only roles can be assumed by AWS services like EC2.

How to eliminate wrong answers

Option A is wrong because an IAM group is a collection of IAM users and cannot be directly attached to an EC2 instance; groups are used to manage permissions for users, not for AWS resources. Option C is wrong because an IAM user has long-term credentials (access key ID and secret access key) that would need to be stored on the EC2 instance, which is a security risk and not a best practice for granting permissions to an AWS service. Option D is wrong because a resource-based policy on the DynamoDB table can grant access to principals (like IAM roles or users) but cannot be attached to an EC2 instance; the EC2 instance itself must have an identity (role) to authenticate against the policy.

162
MCQhard

A company has a requirement that all API calls to AWS must be logged and monitored for suspicious activity. They want to receive alerts when root account activity is detected. Which AWS service and configuration should they use?

A.Enable AWS CloudTrail and configure SNS notifications for root account events.
B.Enable AWS CloudTrail and create a CloudWatch Events rule to match root account API calls and trigger a Lambda function.
C.Use VPC Flow Logs to capture API calls and analyze with Athena.
D.Use AWS Config rules to detect root account usage.
AnswerB

This option correctly outlines the standard and most effective architecture for real-time alerting on specific AWS API calls, such as root account usage. AWS CloudTrail captures all API activity, which can then be streamed to CloudWatch Logs. A CloudWatch Events rule (now often referred to as Amazon EventBridge) can be configured to filter these log events for specific patterns, like API calls made by the root user. Upon a match, the rule can reliably trigger an AWS Lambda function, which can then perform custom actions such as sending detailed alerts, enriching data, or initiating automated remediation.

Why this answer

AWS CloudTrail captures all API calls, including those made by the root account. By creating a CloudWatch Events (now Amazon EventBridge) rule that matches the `userIdentity.type` field set to `Root` and the `eventSource` set to `signin.amazonaws.com`, you can trigger a Lambda function to send alerts or perform remediation. This provides real-time monitoring and notification for suspicious root account activity.

Exam trap

The trap here is confusing CloudTrail's logging capability with direct notification configuration—candidates often think SNS can be attached directly to CloudTrail, but CloudTrail requires an intermediary like CloudWatch Events to filter and route events to SNS or Lambda.

How to eliminate wrong answers

Option A is wrong because while CloudTrail logs root account events, SNS notifications cannot be directly configured on CloudTrail; you need a CloudWatch Events rule to filter and route the events to an SNS topic. Option C is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) at layer 3/4, not API call details; they cannot log or monitor AWS API calls. Option D is wrong because AWS Config rules evaluate resource configuration compliance (e.g., whether an S3 bucket is public), not user activity or API call patterns; they cannot detect root account usage.

163
MCQhard

A company has an IAM policy that allows access to an S3 bucket only if the request comes from a specific VPC endpoint. The developer notices that requests from an EC2 instance in that VPC are being denied. What is the most likely cause?

A.The VPC endpoint policy does not allow the required S3 action for the principal
B.The bucket policy does not have a condition checking aws:SourceVpce
C.The route table does not have a route to the S3 endpoint
D.The security group does not allow outbound HTTPS traffic
AnswerA

A VPC endpoint policy acts as an explicit access control layer for requests originating from within your VPC to AWS services like S3. If this policy does not explicitly permit the required S3 action, such as 's3:GetObject', for the requesting principal, it will override any permissions granted by the IAM user/role policy or the S3 bucket policy. This results in an 'Access Denied' error because the request is blocked at the endpoint before reaching the S3 bucket's own policy evaluation.

Why this answer

The VPC endpoint policy is an additional layer of access control that can explicitly deny actions even if the bucket policy allows them. If the endpoint policy does not grant the required S3 action (e.g., s3:GetObject) for the IAM principal (the EC2 instance's role), requests will be denied regardless of the bucket policy. This is a common misconfiguration where developers focus only on the bucket policy and overlook the endpoint policy.

Exam trap

The trap here is that candidates assume the bucket policy is the only control point and overlook the VPC endpoint policy, which acts as a separate authorization layer that can silently deny requests even when the bucket policy appears correct.

How to eliminate wrong answers

Option B is wrong because the bucket policy condition checking aws:SourceVpce is necessary to restrict access to the VPC endpoint, but the question states the policy already allows access only from a specific VPC endpoint; the issue is that requests are denied, so the condition is likely present but the endpoint policy is blocking. Option C is wrong because the route table does not need a route to the S3 endpoint; VPC endpoints use prefix lists and route tables direct traffic to the endpoint via a gateway or interface endpoint, but missing routes would cause a timeout or connection failure, not an IAM denial. Option D is wrong because security groups do not apply to VPC endpoint traffic; S3 uses a gateway endpoint which is not associated with security groups, and outbound HTTPS traffic from the EC2 instance is allowed by default in the VPC.

164
MCQhard

A developer attaches the following IAM policy: ```json { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "ec2:RunInstances", "Resource": "*" }, { "Effect": "Deny", "Action": "ec2:RunInstances", "Resource": "*", "Condition": { "StringNotEquals": { "ec2:InstanceType": "t2.micro" } } } ] } ``` What happens when the developer attempts to launch a t2.micro instance?

A.The action is denied because ec2:RunInstances requires additional permissions.
B.The action is allowed because the Allow statement applies and the Deny condition excludes t2.micro.
C.The action is denied because the Deny statement overrides the Allow.
D.The action is allowed only if the user has ec2:DescribeInstances as well.
AnswerB

Correct. In IAM, a request is implicitly denied if no Allow matches, but here the Allow for ec2:RunInstances matches the action and applies to the principal. The Deny statement includes a condition that evaluates to false for t2.micro, so it does not apply. Because there is no applicable Deny and at least one applicable Allow, the launch proceeds successfully.

Why this answer

AWS IAM evaluates all applicable statements, and an explicit Deny always overrides an Allow — but only when the Deny's condition evaluates to true. Here the Deny uses StringNotEquals on ec2:InstanceType with value t2.micro, so for a t2.micro launch the condition is false and the Deny does not apply. The Allow on ec2:RunInstances with Resource '*' therefore takes effect and the launch is permitted.

Exam trap

DVA-C02 often tests the misconception that 'Deny always overrides Allow' unconditionally — the real rule is that a Deny only overrides when its condition evaluates true, so candidates who ignore the StringNotEquals condition pick option C.

How to eliminate wrong answers

Option A is wrong because ec2:RunInstances does not require additional permissions to succeed on its own — the policy already grants it, and no dependent action like iam:PassRole is needed for a simple instance launch without an instance profile. Option C is wrong because while Deny normally overrides Allow, that only holds when the Deny statement's condition is satisfied; here StringNotEquals evaluates false for t2.micro, so the Deny is inert. Option D is wrong because ec2:DescribeInstances is a separate read permission not required to call RunInstances; IAM does not implicitly require describe permissions for launch.

165
MCQmedium

A company has an Amazon S3 bucket (Bucket-A) in Account A that contains sensitive data. A developer in Account B needs read-only access to objects in Bucket-A. The developer in Account A added a bucket policy granting s3:GetObject to the IAM user in Account B. However, the IAM user in Account B still receives Access Denied errors. What additional step is required?

A.Add an S3 bucket ACL granting the user in Account B Read access
B.Create an IAM policy in Account B that allows s3:GetObject for the specific bucket and attach it to the user
C.Generate a pre-signed URL for each object and share it with the user
D.Add a condition in the bucket policy to allow requests only from the user's IP address
AnswerB

For cross-account access to an S3 bucket, the "two-account" principle dictates that both the resource owner (Account A) and the principal's account (Account B) must explicitly grant permission. The bucket policy in Account A would permit s3:GetObject for the principal in Account B, and this IAM policy in Account B would then authorize the specific user to perform s3:GetObject on the designated bucket. This combined approach ensures the user has the necessary permissions from both sides of the trust relationship.

Why this answer

The bucket policy in Account A grants access to the IAM user in Account B, but the user's identity in Account B must also have an explicit IAM policy that allows the s3:GetObject action. Without this, the user in Account B lacks the necessary permissions to access the bucket, even though the bucket policy permits it. This is because cross-account access requires both a resource-based policy (bucket policy) in the source account and an identity-based policy (IAM policy) in the target account to authorize the request.

Exam trap

The trap here is that candidates often assume a bucket policy alone is sufficient for cross-account access, forgetting that the IAM user in the target account must also have an explicit allow policy for the action.

How to eliminate wrong answers

Option A is wrong because S3 bucket ACLs are legacy and do not support granting access to IAM users in another AWS account; they only grant access to AWS accounts or predefined groups, not specific IAM users. Option C is wrong because generating pre-signed URLs is a workaround for temporary access, not a required step to fix the existing bucket policy and IAM user configuration; it would bypass the need for proper IAM policies but is not the missing step for the described setup. Option D is wrong because adding an IP address condition is unrelated to the cross-account permission issue; it would restrict access based on network location but does not resolve the missing identity-based policy in Account B.

166
MCQmedium

A company is using an S3 bucket to store sensitive documents. They need to ensure that all objects are encrypted at rest using server-side encryption with AWS KMS. The bucket policy must enforce encryption by denying uploads that do not specify the required encryption. Which bucket policy statement should be added?

A.Condition: StringNotEquals: 's3:x-amz-server-side-encryption': 'aws:kms'
B.Condition: StringEquals: 's3:x-amz-server-side-encryption-aws:kms': 'true'
C.Condition: Null: 's3:x-amz-server-side-encryption': 'true'
D.Condition: StringNotEquals: 's3:x-amz-server-side-encryption': 'AES256'
AnswerA

This policy statement uses a Deny effect (implied by the question context of enforcing a specific encryption type) combined with the StringNotEquals condition. It explicitly denies any s3:PutObject request where the s3:x-amz-server-side-encryption header value is not 'aws:kms'. This effectively mandates that all uploaded objects must specify 'aws:kms' for server-side encryption, thereby enforcing the use of AWS KMS (SSE-KMS) for sensitive documents.

Why this answer

The bucket policy uses the `s3:x-amz-server-side-encryption` condition key with `StringNotEquals` to deny any upload where the header does not specify `aws:kms`. This ensures that only objects encrypted with AWS KMS (SSE-KMS) are allowed, enforcing server-side encryption at rest. The `Deny` effect combined with this condition blocks requests that either omit the encryption header or specify a different value like `AES256`.

Exam trap

The trap here is that candidates often confuse the condition key `s3:x-amz-server-side-encryption` with the KMS-specific key `s3:x-amz-server-side-encryption-aws:kms` (which does not exist), or they mistakenly use `Null` to check for the header's presence without validating its value, allowing SSE-S3 (AES256) uploads to bypass the policy.

How to eliminate wrong answers

Option B is wrong because `s3:x-amz-server-side-encryption-aws:kms` is not a valid condition key; the correct key is `s3:x-amz-server-side-encryption` and the value should be `aws:kms`, not a boolean. Option C is wrong because using `Null: 's3:x-amz-server-side-encryption': 'true'` only denies requests where the header is absent, but it does not enforce that the encryption type is `aws:kms`; a request with `AES256` would still be allowed. Option D is wrong because `StringNotEquals: 's3:x-amz-server-side-encryption': 'AES256'` denies requests that do not use AES256, which would incorrectly allow `aws:kms` but also block legitimate SSE-KMS uploads if the policy is meant to require KMS; it also fails to block requests with no encryption header.

167
MCQmedium

A developer receives an AccessDenied error when trying to upload a file to an S3 bucket that has a bucket policy requiring encryption in transit. What is the most likely cause?

A.The object is not encrypted with server-side encryption
B.The IAM user does not have s3:PutObject permission
C.The request signature is expired
D.The request is not using HTTPS
AnswerD

Amazon S3 bucket policies can enforce conditions on incoming requests, including requiring secure transport. The `aws:SecureTransport` condition key evaluates to `true` only when a request is made over HTTPS, ensuring data is encrypted in transit. If a bucket policy contains a `Deny` statement for `s3:PutObject` actions where `aws:SecureTransport` is `false`, then any attempt to upload an object using unencrypted HTTP will violate this policy condition, resulting in an `AccessDenied` error because the request did not use HTTPS for encryption in transit.

Why this answer

A bucket policy that requires encryption in transit typically uses a condition like aws:SecureTransport: true, which evaluates to false for HTTP requests. If the SDK or client sends the PutObject request over HTTP instead of HTTPS, the condition fails and S3 returns AccessDenied. The most likely cause is that the request is not using HTTPS.

Exam trap

DVA-C02 often tests the distinction between encryption at rest and encryption in transit — candidates see 'encryption' in the bucket policy and incorrectly assume SSE is missing, when the condition is actually about HTTPS.

How to eliminate wrong answers

Option A is wrong because encryption at rest (SSE) is a separate concern from encryption in transit; the bucket policy in question enforces TLS, not SSE. Option B is wrong because missing s3:PutObject permission would also cause AccessDenied, but the question specifies the policy requires encryption in transit — the condition is the differentiator. Option C is wrong because an expired signature produces a distinct SignatureDoesNotMatch or RequestTimeTooSkewed error, not the SecureTransport condition failure.

168
Multi-Selecthard

A developer is troubleshooting an AccessDenied error when a Lambda function tries to write to CloudWatch Logs. The function's IAM role includes the following policy. Which TWO missing permissions are causing the error? (Choose TWO.)

Select 2 answers
A.logs:DescribeLogStreams
B.logs:CreateLogGroup
C.logs:CreateLogStream
D.logs:GetLogEvents
E.logs:PutLogEvents
AnswersC, E

The logs:CreateLogStream permission is absolutely essential for an application to establish a new log stream within an existing CloudWatch Log Group. If the application attempts to write log events to a stream that does not yet exist, and it lacks this specific permission, it will inevitably encounter an AccessDenied error. This permission enables the necessary infrastructure for subsequent PutLogEvents calls to succeed.

Why this answer

A Lambda function must call logs:CreateLogStream before it can write log events to a specific log stream. Without this permission, the function cannot create a new log stream when one does not already exist, resulting in an AccessDenied error. Option E is correct because logs:PutLogEvents is the permission required to actually write log events to an existing log stream; without it, the function cannot send log data to CloudWatch Logs.

Exam trap

The trap here is that candidates often assume only PutLogEvents is needed for writing logs, forgetting that the Lambda runtime must also create the log stream if it does not already exist, making CreateLogStream a required permission.

169
MCQhard

A company has a multi-account AWS environment using AWS Organizations. The security team wants to enforce that all S3 buckets across all accounts are encrypted with AES-256 using SSE-S3. They also want to automatically remediate any bucket that is created without encryption. The team currently uses AWS CloudFormation StackSets to deploy resources. They need a solution that does not require manual intervention. Which approach should be taken?

A.Create an SCP that denies s3:PutBucketEncryption with a condition that the encryption is not SSE-S3.
B.Configure an AWS Config rule to detect buckets without SSE-S3 and use AWS Systems Manager Automation to apply SSE-S3 encryption automatically.
C.Create a CloudFormation template that includes a bucket with SSE-S3 enabled and deploy it via StackSets to all accounts.
D.Enable S3 Block Public Access at the organization level.
AnswerB

AWS Config provides continuous monitoring of resource configurations against desired states. A managed Config rule, such as s3-bucket-server-side-encryption-enabled, can detect S3 buckets that do not have server-side encryption enabled or do not meet the specified SSE-S3 requirement. Upon detection of non-compliance, AWS Config can trigger an AWS Systems Manager Automation document, which can then execute the necessary API calls (e.g., PutBucketEncryption) to automatically apply SSE-S3 encryption to the non-compliant buckets, ensuring ongoing compliance and remediation.

Why this answer

AWS Config can continuously evaluate S3 buckets against a custom rule that checks for SSE-S3 encryption. When a non-compliant bucket is detected, AWS Systems Manager Automation can automatically remediate it by applying the required encryption, meeting the requirement for automatic remediation without manual intervention.

Exam trap

The trap here is that candidates may confuse preventive controls (SCPs) with detective and corrective controls (Config + Automation), failing to realize that SCPs alone cannot remediate already non-compliant resources or enforce encryption on buckets created without encryption settings.

How to eliminate wrong answers

Option A is wrong because an SCP that denies s3:PutBucketEncryption would prevent any encryption changes, but it does not enforce encryption on newly created buckets (which default to no encryption) and does not provide automatic remediation. Option C is wrong because deploying a CloudFormation template via StackSets only creates buckets with encryption at deployment time; it does not detect or remediate buckets created outside of CloudFormation, such as those created manually or by other services. Option D is wrong because S3 Block Public Access controls public access settings, not encryption; it does not address the requirement to enforce SSE-S3 encryption.

170
MCQhard

A developer is deploying an application on EC2 that must access an S3 bucket. The developer wants to avoid hard-coding credentials. What is the MOST secure way to grant access?

A.Use an S3 bucket policy that allows access from the EC2 instance's public IP address.
B.Create an IAM role and attach it to the EC2 instance profile.
C.Set the AWS credentials as environment variables in the user data script.
D.Store the AWS access key ID and secret access key in a configuration file on the instance.
AnswerB

Creating an IAM role and attaching it to an EC2 instance profile is the AWS-recommended and most secure method for granting permissions. The instance profile acts as a container for the IAM role, allowing the EC2 instance to assume the role and obtain temporary, frequently rotated credentials from the EC2 metadata service. This eliminates the need to store long-term AWS credentials directly on the instance, significantly reducing the risk of credential compromise and adhering to the principle of least privilege.

Why this answer

Attaching an IAM role to the EC2 instance profile lets the instance obtain temporary, automatically rotated credentials from the EC2 instance metadata service (IMDS), so no long-lived secrets exist on the instance or in code. This is the AWS-recommended best practice for EC2-to-S3 access and eliminates the risk of credential leakage. The SDKs and CLI automatically retrieve and refresh these credentials.

Exam trap

DVA-C02 often tests the misconception that environment variables or config files are acceptable for credentials, when the correct answer is always instance profiles with IAM roles for EC2 workloads.

How to eliminate wrong answers

Option A is wrong because an S3 bucket policy keyed on a public IP is fragile (IPs change on stop/start), exposes the bucket to anyone behind that IP, and does not authenticate the instance identity. Option C is wrong because user data scripts are stored in plaintext and visible via the EC2 console and metadata, so embedding credentials there leaks them. Option D is wrong because storing long-lived access keys in a config file on the instance creates a persistent secret that can be exfiltrated and must be manually rotated.

171
MCQmedium

A developer is building a serverless application using AWS Lambda and API Gateway. The Lambda function needs to access a DynamoDB table that stores sensitive customer data. The developer wants to follow the principle of least privilege. Which IAM role configuration should be used?

A.Configure a resource-based policy on the Lambda function to allow DynamoDB access.
B.Attach the AmazonDynamoDBFullAccess managed policy to the Lambda execution role.
C.Use an S3 bucket policy to grant the Lambda function access to the DynamoDB table.
D.Create a custom IAM policy with specific DynamoDB actions (e.g., GetItem, PutItem) on the specific table and attach it to the Lambda execution role.
AnswerD

Creating a custom IAM policy with specific DynamoDB actions (e.g., GetItem, PutItem) on the specific table and attaching it to the Lambda execution role is the correct and most secure approach. This method strictly adheres to the principle of least privilege by granting only the precise actions required (e.g., `dynamodb:GetItem`, `dynamodb:PutItem`) on the exact DynamoDB table resource (specified by its ARN), minimizing potential security risks and ensuring the function has only necessary permissions.

Why this answer

It adheres to the principle of least privilege by granting only the specific DynamoDB actions (e.g., GetItem, PutItem) required by the Lambda function, scoped to the exact table. The Lambda execution role is an IAM role that the Lambda service assumes, and attaching a custom policy with fine-grained permissions ensures minimal access. This approach avoids over-permissioning and follows AWS security best practices for serverless applications.

Exam trap

The trap here is that candidates confuse resource-based policies (used for granting invoke permissions to Lambda) with execution role policies (used for granting the Lambda function access to other AWS services), leading them to pick Option A, which does not control DynamoDB access.

How to eliminate wrong answers

Option A is wrong because resource-based policies on Lambda functions control which other AWS services or accounts can invoke the function, not the function's own access to downstream resources like DynamoDB; Lambda uses execution roles for outbound permissions. Option B is wrong because AmazonDynamoDBFullAccess is a managed policy that grants unrestricted access to all DynamoDB actions on all tables, violating the principle of least privilege. Option C is wrong because S3 bucket policies are used to control access to S3 resources, not DynamoDB tables; DynamoDB access is governed by IAM policies attached to the caller's role, not by S3 policies.

172
MCQhard

The exhibit shows an IAM policy attached to a Lambda function's execution role. When the Lambda function tries to decrypt data using the KMS key, it receives an access denied error. What is the most likely cause?

A.The policy uses an incorrect action name for decryption.
B.The KMS key policy does not grant the Lambda execution role permission to use the key.
C.The policy does not include kms:DescribeKey permission.
D.The policy does not include kms:Decrypt permission.
AnswerB

AWS KMS enforces a two-layer authorization model, requiring both an identity-based policy (IAM policy) attached to the principal (like the Lambda execution role) and a resource-based policy (KMS key policy) attached to the key itself to grant permission. Even if the Lambda's IAM policy correctly allows `kms:Decrypt`, if the target KMS key's policy does not also explicitly permit the Lambda's execution role to use the key, the decryption request will be denied. This is a common and critical misconfiguration.

Why this answer

The most likely cause is that the KMS key policy does not grant the Lambda execution role permission to use the key. Even if the IAM policy attached to the role includes kms:Decrypt, the KMS key policy must also allow the role to use the key. KMS requires both identity-based and resource-based policies to grant access.

Exam trap

DVA-C02 often tests KMS access where both IAM policies and key policies are required. Candidates may only check the IAM policy and forget the key policy, leading to access denied errors.

How to eliminate wrong answers

Option A is wrong because the action name for decryption is correct (kms:Decrypt). Option C is wrong because kms:DescribeKey is not required for decryption; it is used to get key metadata. Option D is wrong because the policy likely includes kms:Decrypt; the issue is the key policy, not the IAM policy.

173
MCQmedium

A mobile application must let authenticated users upload only to their own S3 prefix. Which approach best follows least privilege?

A.Use Cognito identity credentials with an IAM policy scoped to the user's prefix using policy variables
B.Use a single hardcoded access key in the app
C.Make the bucket public and validate names in the client
D.Give every user AmazonS3FullAccess
AnswerA

This is the correct approach because AWS Cognito Identity Pools can issue temporary, fine-grained AWS credentials to authenticated users. An associated IAM policy can then leverage policy variables, such as ${cognito-identity.amazonaws.com:sub}, to dynamically scope S3 upload permissions to a specific user's unique prefix within a bucket. This ensures each user can only write to their designated folder, fulfilling the requirement for authenticated users to upload only to their own specific location.

Why this answer

It uses Amazon Cognito identity pools to issue temporary AWS credentials scoped to a specific S3 prefix via IAM policy variables (e.g., `${cognito-identity.amazonaws.com:sub}`). This ensures each authenticated user can only upload to their own prefix (e.g., `uploads/${user_id}/`), adhering to the principle of least privilege by granting no more access than necessary.

Exam trap

The trap here is that candidates might choose Option B (hardcoded key) thinking it's simpler, missing that it exposes a static credential that can be compromised, or Option C (public bucket) assuming client-side validation is sufficient, when in fact AWS requires server-side enforcement for security.

How to eliminate wrong answers

Option B is wrong because hardcoding a single access key in the app violates security best practices — the key could be extracted from the mobile binary, granting unrestricted access to the entire bucket. Option C is wrong because making the bucket public and validating names client-side is insecure; a malicious user can bypass client-side checks and upload to any prefix. Option D is wrong because granting AmazonS3FullAccess to every user violates least privilege by giving all users full administrative control over all S3 buckets, including the ability to delete or modify any object.

174
MCQhard

A developer is deploying an application on Amazon EC2 that needs to access an Amazon RDS database. The security team requires that database credentials are automatically rotated every 30 days and that the application retrieves them securely. Which solution should the developer implement?

A.Create an IAM database authentication token for RDS and configure the application to generate a new token every 30 days.
B.Store the database credentials in AWS Systems Manager Parameter Store as a SecureString parameter and enable automatic rotation using a Lambda function.
C.Use AWS Secrets Manager to store the database credentials and configure automatic rotation using the built-in RDS rotation function.
D.Store the credentials in an encrypted Amazon S3 object and use an S3 event notification to trigger a Lambda function that rotates the password every 30 days.
AnswerC

AWS Secrets Manager is designed for managing and rotating secrets. It provides built-in integration with Amazon RDS to automatically rotate credentials on a schedule. The application can retrieve the current credentials using the Secrets Manager API or SDK, ensuring secure access. This meets both the rotation and secure retrieval requirements.

Why this answer

AWS Secrets Manager provides native support for rotating RDS database credentials using a Lambda rotation function. It automatically updates the password in both the database and the secret, and the application retrieves the current credentials via API. This satisfies the rotation and secure retrieval requirements with minimal custom code.

Exam trap

The trap here is assuming Parameter Store offers automatic rotation for RDS; it does not, and custom rotation is required, which is not the best practice.

175
MCQhard

An application running on EC2 instances in an Auto Scaling group needs to access an S3 bucket. The security team wants to avoid storing long-term AWS credentials on the instances. Which approach should be used?

A.Store the credentials in AWS Systems Manager Parameter Store and retrieve them in User Data.
B.Create an IAM role and attach it to the EC2 instance profile.
C.Use an AWS Lambda function to generate temporary credentials and pass them to the instances.
D.Generate access keys for a dedicated IAM user and store them in a file on the AMI.
AnswerB

Attaching an IAM role to an EC2 instance via an instance profile is the recommended best practice. This allows applications running on the instance to automatically obtain temporary, frequently rotated security credentials from the EC2 instance metadata service. AWS SDKs and CLI tools are designed to seamlessly retrieve these credentials, eliminating the need to store or manage any long-term access keys directly on the instance, thereby significantly enhancing security.

Why this answer

It uses an IAM role attached to an EC2 instance profile, which allows the EC2 instances to automatically obtain temporary security credentials from the AWS Security Token Service (STS). This approach eliminates the need to store long-term credentials on the instances, as the credentials are rotated automatically and are retrieved via the instance metadata service (IMDS).

Exam trap

The trap here is that candidates may think storing credentials in Parameter Store or using Lambda to generate temporary credentials is more secure, but they overlook that an IAM role with an instance profile is the simplest and most secure method because it eliminates the need to handle credentials at all.

How to eliminate wrong answers

Option A is wrong because storing credentials in Systems Manager Parameter Store and retrieving them in User Data still requires the credentials to be stored as a secret, and User Data runs only at instance launch, leaving the credentials on the instance's local storage or memory, which violates the security requirement of not storing long-term credentials. Option C is wrong because using an AWS Lambda function to generate temporary credentials and pass them to the instances introduces unnecessary complexity and a potential security risk of passing credentials over the network; the instances can directly obtain temporary credentials via an IAM role without external orchestration. Option D is wrong because generating access keys for a dedicated IAM user and storing them in a file on the AMI embeds long-term credentials directly into the AMI, which persists across instances and violates the core security principle of avoiding stored credentials.

176
MCQhard

A company stores sensitive data in Amazon S3. A developer needs to implement a solution that automatically encrypts objects at rest using a key that is rotated annually. The developer must minimize operational overhead. Which solution meets these requirements?

A.Use Server-Side Encryption with S3-Managed Keys (SSE-S3) and set key rotation policy.
B.Use Server-Side Encryption with AWS KMS-Managed Keys (SSE-KMS) with automatic key rotation.
C.Use Server-Side Encryption with Customer-Provided Keys (SSE-C) and manually rotate keys.
D.Use Client-Side Encryption with KMS.
AnswerB

SSE-KMS leverages AWS Key Management Service (KMS) to manage the encryption keys. For customer-managed keys (CMKs) in KMS, you can easily enable automatic key rotation, which rotates the backing key material annually. This feature directly satisfies the requirement for annual key rotation with minimal operational overhead, as KMS handles the rotation process seamlessly without requiring manual intervention.

Why this answer

SSE-KMS with automatic key rotation meets the requirement for annual key rotation with minimal operational overhead because AWS KMS can automatically rotate the customer master key (CMK) every year (365 days) without any manual intervention. This ensures that objects in S3 are encrypted at rest using a key that is rotated on schedule, while the developer does not need to manage the rotation process.

Exam trap

The trap is that SSE-S3 rotates its keys automatically every day, not annually. Candidates may assume SSE-S3 provides annual rotation like KMS, leading them to incorrectly choose option A. Actually, SSE-S3 key rotation is fixed and cannot be customized; only SSE-KMS allows configurable key rotation (e.g., yearly) with automatic key management.

How to eliminate wrong answers

Option A is wrong because SSE-S3 does not support customer-controlled key rotation; S3 manages the keys entirely and rotates them automatically every year, but the developer cannot set or control a custom key rotation policy. Option C is wrong because SSE-C requires the developer to provide and manage their own encryption keys, including manually rotating them, which increases operational overhead. Option D is wrong because client-side encryption requires the developer to implement encryption logic in the application and manage key rotation on the client side, adding significant operational overhead compared to a server-side solution.

177
MCQeasy

A developer needs to securely store database credentials for a Lambda function. The credentials must be automatically rotated every 90 days. Which AWS service should be used?

A.AWS Secrets Manager
B.AWS Systems Manager Parameter Store
C.Amazon DynamoDB
D.AWS KMS
AnswerA

AWS Secrets Manager is the correct choice because it is purpose-built for securely storing, managing, and retrieving sensitive credentials like database passwords, API keys, and other secrets. A key feature is its ability to automatically rotate secrets, including integrating with databases to generate new credentials and update the database directly. This automation significantly enhances security by regularly changing credentials without manual intervention, reducing the risk of compromise and ensuring compliance with security best practices.

Why this answer

AWS Secrets Manager is the correct service because it is designed specifically for securely storing, managing, and automatically rotating database credentials and other secrets. It supports built-in rotation with AWS Lambda, allowing you to set a custom rotation interval (e.g., 90 days) without custom infrastructure. Secrets Manager also integrates natively with Amazon RDS, Redshift, and DocumentDB for automatic credential rotation.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store (which can store secrets securely but lacks automatic rotation) with AWS Secrets Manager, leading them to choose Parameter Store when the question explicitly requires automatic rotation.

How to eliminate wrong answers

Option B (AWS Systems Manager Parameter Store) is wrong because while it can store secrets securely, it does not support automatic rotation of credentials out of the box; you would need to build custom rotation logic. Option C (Amazon DynamoDB) is wrong because it is a NoSQL database service, not a secrets management service, and storing credentials there would require manual encryption and rotation, violating security best practices. Option D (AWS KMS) is wrong because it is a key management service for creating and controlling encryption keys, not for storing or rotating secrets; it can be used to encrypt secrets but does not manage the secret lifecycle or rotation.

178
Drag & Dropmedium

Drag and drop the steps to set up a DynamoDB table with auto scaling in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order for setting up DynamoDB auto scaling is: first create the DynamoDB table with provisioned capacity, then create an Application Auto Scaling target for the table, then define the scaling policies (for read and write capacity), and finally apply the policies to the target. The target must be registered before policies can be defined.

Exam trap

A common pitfall is defining scaling policies before creating the scaling target. The target must exist first for policies to reference it.

179
MCQmedium

A developer needs to allow an IAM user in a different AWS account to assume a role in the developer's account. The role has permissions to access an S3 bucket. Which policy is required in the developer's account to enable this cross-account access?

A.An IAM role with a trust policy that allows the external account's root user or specific IAM users/roles to assume the role
B.An S3 bucket policy granting access to the external account
C.An IAM user policy in the external account allowing sts:AssumeRole
D.An AWS Organizations service control policy allowing cross-account access
AnswerA

This is the correct mechanism for cross-account role assumption. An IAM role's trust policy (also known as an assume role policy) explicitly defines which AWS principals, including users or roles from other AWS accounts, are permitted to assume that role. By specifying the external account ID or a specific ARN of an IAM user/role within the `Principal` element of the trust policy, the role establishes the necessary cross-account trust relationship, allowing the external entity to temporarily gain the role's permissions.

Why this answer

Cross-account IAM role access requires a trust policy attached to the role in the developer's account. This trust policy specifies the external AWS account ID (or specific IAM users/roles in that account) as the principal, allowing them to call sts:AssumeRole. Once the role is assumed, the developer's account grants the necessary S3 permissions via the role's permissions policy.

Exam trap

The trap here is that candidates often confuse the location of the trust policy (required in the account owning the role) with the permissions policy (required in the external account), or mistakenly think an S3 bucket policy alone can enable cross-account role assumption.

How to eliminate wrong answers

Option B is wrong because an S3 bucket policy alone cannot enable the initial assumption of a role; it only grants direct access to the bucket, not the ability to assume an IAM role. Option C is wrong because an IAM user policy in the external account allowing sts:AssumeRole is necessary but not sufficient—the developer's account must also have a trust policy that accepts the assumption request; the question asks for the policy required in the developer's account. Option D is wrong because AWS Organizations SCPs can restrict permissions but cannot grant cross-account access; they are used to set permission boundaries, not to allow role assumption.

180
MCQhard

A company uses AWS CloudTrail to log all API calls. The security team wants to be notified immediately when an IAM user creates a new access key. Which solution is most efficient?

A.Configure CloudTrail to send logs to CloudWatch Logs and create a metric filter with an alarm.
B.Create a CloudWatch Events rule that matches the CreateAccessKey API call and triggers a Lambda function to send an SNS notification.
C.Enable CloudTrail log file validation and periodically check the logs.
D.Use Amazon Athena to query CloudTrail logs daily.
AnswerB

This is the most effective solution for real-time security notifications. CloudWatch Events (now Amazon EventBridge) can directly consume CloudTrail management events as they occur, allowing for immediate pattern matching on specific API calls like CreateAccessKey. Upon a match, it can instantly invoke a Lambda function, which then sends an SNS notification, ensuring near-instantaneous alerting for critical security events.

Why this answer

CloudWatch Events (now Amazon EventBridge) can directly match the CreateAccessKey API call from CloudTrail and trigger a Lambda function to send an SNS notification in near real-time. This is the most efficient solution as it avoids the overhead of log ingestion, metric filters, or periodic queries, providing immediate notification with minimal latency.

Exam trap

The trap here is that candidates often default to CloudWatch Logs metric filters (Option A) because they are familiar, but fail to recognize that EventBridge rules provide a simpler, lower-latency, and more cost-effective solution for real-time API call monitoring.

How to eliminate wrong answers

Option A is wrong because it requires sending CloudTrail logs to CloudWatch Logs and creating a metric filter with an alarm, which introduces additional cost, latency, and complexity compared to a direct EventBridge rule. Option C is wrong because CloudTrail log file validation only verifies file integrity, not real-time monitoring, and periodically checking logs is not immediate. Option D is wrong because using Athena to query CloudTrail logs daily provides only periodic, not immediate, notification and is inefficient for real-time alerting.

181
MCQeasy

A developer needs to securely store database credentials for an application running on AWS Lambda. Which AWS service should they use?

A.AWS Systems Manager Session Manager
B.AWS CloudHSM
C.AWS Systems Manager Parameter Store (Standard tier)
D.AWS Secrets Manager
AnswerD

AWS Secrets Manager is purpose-built for storing sensitive credentials like database passwords, encrypting them at rest with KMS, and supports native automatic rotation integrations with RDS, Redshift, and DocumentDB so credentials can be rotated on a schedule without manual intervention or application downtime.

Why this answer

AWS Secrets Manager (option D) is correct because it is purpose-built to store, encrypt, and manage secrets such as database credentials, and it supports automatic rotation via Lambda functions and native integration with RDS, Redshift, and DocumentDB. For a Lambda application, the code can retrieve credentials at runtime using the AWS SDK (GetSecretValue) with IAM permissions, so credentials are never hard-coded. Option A, Session Manager, is for interactive shell access to EC2 instances, not secret storage.

Option B, CloudHSM, provides dedicated hardware security modules for key operations but is not a credentials store. Option C, Parameter Store Standard tier, can hold SecureString values, but it lacks built-in secret rotation and is less suited for managing database credentials than Secrets Manager.

182
MCQeasy

An application running on EC2 needs to access an S3 bucket. What is the most secure way to grant access?

A.Generate an IAM user access key and store it in a file on the instance
B.Use pre-signed URLs for each request
C.Make the S3 bucket public
D.Create an IAM role with S3 permissions and attach it to the EC2 instance
AnswerD

Creating an IAM role with the necessary S3 permissions and attaching it to the EC2 instance is the secure and recommended best practice. This method allows the EC2 instance to assume the role, obtaining temporary, automatically rotated credentials from the AWS Security Token Service (STS) via the instance metadata service. This eliminates the need to store any long-lived static credentials on the instance, significantly reducing the risk of credential compromise and simplifying credential management.

Why this answer

Attaching an IAM role to the EC2 instance (D) is the most secure approach because it delivers temporary, automatically rotated credentials to the instance via the Instance Metadata Service (IMDS), eliminating long-lived access keys stored on disk. The role's trust policy allows EC2 to assume it, and the attached permissions policy scopes exactly which S3 actions and resources the instance can access. This follows AWS least-privilege and credential-hygiene best practices.

Exam trap

DVA-C02 often tests credential management — candidates pick access keys stored on the instance because it 'works,' missing that IAM roles provide short-lived, auto-rotated credentials and are the AWS-recommended pattern.

How to eliminate wrong answers

Option A is wrong because generating an IAM user access key and storing it in a file creates long-lived static credentials that can be leaked, committed to source control, or stolen from the instance — a well-known anti-pattern. Option B is wrong because pre-signed URLs are designed for granting time-limited access to specific objects to external or unauthenticated users, not for an application's ongoing programmatic access to a bucket; they also require an existing credential to generate. Option C is wrong because making the bucket public exposes all objects to the internet with no authentication or authorization, violating every security requirement.

183
MCQmedium

A developer is building a web application that stores user session data in an ElastiCache Redis cluster. The cluster is in a VPC and is not publicly accessible. The developer needs to ensure that data in transit is encrypted. What should the developer do?

A.Enable encryption in transit on the ElastiCache Redis cluster.
B.Place an Application Load Balancer in front of the Redis cluster and enable TLS termination.
C.Configure the security group to only allow traffic from the application servers.
D.Use VPC peering to connect the application VPC to the ElastiCache VPC.
AnswerA

Enabling in-transit encryption on the ElastiCache Redis cluster makes clients negotiate TLS, protecting session data as it moves between the application and the cluster. The VPC isolation already handles network reachability, so no security group change is required.

Why this answer

ElastiCache for Redis supports encryption in transit, which encrypts data between the client and the Redis cluster. Placing an Application Load Balancer in front of the Redis cluster (Option B) is not supported; Redis uses a custom protocol that ALB cannot handle. Configuring security groups (Option C) controls network traffic but does not encrypt data.

VPC peering (Option D) allows network connectivity but does not provide encryption in transit.

184
Multi-Selecteasy

A developer needs to encrypt data at rest in an Amazon S3 bucket. Which THREE options are available for server-side encryption?

Select 3 answers
A.SSE-C
B.Client-side encryption
C.SSE-KMS
D.SSE-S3
E.AWS CloudHSM
AnswersA, C, D

SSE-C lets you provide your own encryption keys in every request, and S3 performs the encryption/decryption as objects are written/read. The keys are not stored by AWS; S3 holds only a salted HMAC of the key for validation, so you must supply the raw key on every operation. This meets a customer-managed key requirement while still being server-side encryption.

Why this answer

SSE-C (option A) is a valid server-side encryption option where the customer supplies their own encryption keys to S3, and S3 performs the encryption/decryption on the server side while the customer retains the keys. SSE-KMS (option C) is correct because S3 uses AWS KMS customer master keys (CMKs) to generate and manage the data keys used for server-side encryption, giving audit and control benefits. SSE-S3 (option D) is also correct because S3 fully manages the encryption keys with AES-256, providing server-side encryption without any key management effort from the customer.

Option B (client-side encryption) is not a server-side option since the data is encrypted before it reaches S3, and option E (AWS CloudHSM) is a hardware security module service, not an S3 server-side encryption mode, although it can be used indirectly with SSE-C or custom key management.

Exam trap

DVA-C02 often tests the boundary between server-side and client-side encryption — candidates who pick 'Client-side encryption' as an S3 SSE option miss that SSE by definition means AWS performs encryption after receiving the data.

185
MCQmedium

A developer created the following IAM role for a Lambda function: ```json { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": {"Service": "lambda.amazonaws.com"}, "Action": "sts:AssumeRole" } ] } ``` The function needs to write logs to CloudWatch Logs. What is missing?

A.The role needs a permissions policy that grants logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents.
B.The trust policy is incorrect; it should allow ec2.amazonaws.com.
C.The role name is invalid.
D.The trust policy should not allow Lambda to assume the role.
AnswerA

Lambda functions automatically publish logs to Amazon CloudWatch Logs. For this logging mechanism to function correctly, the IAM execution role assigned to the Lambda function must possess a permissions policy granting specific actions: logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents. Without these essential permissions, the Lambda function will be unable to create its dedicated log resources or write any operational data and errors to CloudWatch, severely impacting monitoring and debugging capabilities.

Why this answer

The role shown includes a trust policy that allows Lambda to assume the role but does not include an attached permissions policy for CloudWatch Logs. To write logs to CloudWatch Logs, the Lambda function must be granted logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents through a permissions policy attached to the role.

Exam trap

The trap here is that candidates may overlook the specific CloudWatch Logs permissions required for Lambda logging and instead focus on trust policy or naming issues, but the missing element is the permissions policy granting the necessary logging actions.

How to eliminate wrong answers

Option B is wrong because the trust policy should allow `lambda.amazonaws.com` (the Lambda service principal) to assume the role, not `ec2.amazonaws.com`, which is used for EC2 instances. Option C is wrong because there is no requirement for a specific role name; IAM role names can be any valid alphanumeric string and are not restricted to a particular format for Lambda. Option D is wrong because the trust policy must allow Lambda to assume the role; without this, the Lambda function cannot obtain temporary credentials to execute and access AWS resources.

186
MCQeasy

A developer needs to securely store database credentials for a serverless application. Which AWS service should be used?

A.AWS Key Management Service (KMS)
B.Amazon DynamoDB
C.AWS Secrets Manager
D.AWS Systems Manager Parameter Store
AnswerC

AWS Secrets Manager is purpose-built for securely storing, managing, and retrieving sensitive credentials like database passwords, API keys, and other secrets. Its core functionality includes automatic rotation of secrets, which significantly enhances security by regularly changing credentials without requiring manual intervention. Additionally, it offers fine-grained access control, auditing through CloudTrail, and integration with other AWS services, making it the optimal choice for secure credential management.

Why this answer

AWS Secrets Manager is the correct service because it is purpose-built for securely storing, rotating, and managing database credentials and other secrets throughout their lifecycle. It integrates natively with Amazon RDS, Redshift, and DocumentDB to automatically rotate credentials, and it enforces encryption at rest using AWS KMS. For a serverless application, Secrets Manager provides a simple API call (e.g., GetSecretValue) to retrieve credentials without hardcoding them in code or environment variables.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store (which can store secrets but lacks automatic rotation and deep RDS integration) with AWS Secrets Manager, leading them to choose Parameter Store when the question explicitly requires secure storage and management of database credentials for a serverless application.

How to eliminate wrong answers

Option A is wrong because AWS Key Management Service (KMS) is a managed service for creating and controlling encryption keys, not for storing secrets like database credentials; it can encrypt secrets but does not provide secret rotation or retrieval APIs. Option B is wrong because Amazon DynamoDB is a NoSQL database designed for high-performance key-value and document storage, not a secure secrets store; storing credentials there would require manual encryption and lack built-in rotation, access auditing, or automatic secret management. Option D is wrong because AWS Systems Manager Parameter Store is a service for storing configuration data and secrets, but it lacks native automatic rotation for database credentials (unless combined with a custom Lambda function) and does not offer the same level of integration with RDS or secret-specific features like cross-account access or secret versioning with staging labels.

187
MCQhard

A developer stores database credentials in Secrets Manager. The application sometimes receives AccessDeniedException from Lambda after secret rotation. What should be checked first?

A.Whether API Gateway caching is enabled
B.Whether the Lambda execution role and KMS key policy allow access to the new secret version and key
C.Whether the VPC has exactly three subnets
D.Whether CloudFront invalidation completed
AnswerB

When a Lambda function attempts to retrieve a secret from AWS Secrets Manager, it requires specific IAM permissions. The Lambda execution role must possess `secretsmanager:GetSecretValue` permission for the target secret. Furthermore, if the secret is encrypted using a customer-managed AWS Key Management Service (KMS) key, the Lambda execution role must also be granted `kms:Decrypt` permission on that specific KMS key. Without these explicit permissions on both the role and the KMS key policy, especially for new secret versions or keys, access will be denied.

Why this answer

The AccessDeniedException from Lambda after secret rotation indicates that the Lambda function cannot access the new secret version. This is most commonly caused by the Lambda execution role lacking the necessary permissions (e.g., secretsmanager:GetSecretValue) for the new secret version ARN, or the KMS key policy not granting the Lambda role access to decrypt the secret using the customer-managed KMS key. Checking these two policies first is the correct troubleshooting step because rotation creates a new version with a different ARN, and the IAM policy must allow access to all versions or use a wildcard.

Exam trap

The trap here is that candidates may overlook the KMS key policy and focus only on the Lambda execution role, but the AccessDeniedException can also stem from the KMS key not authorizing the Lambda role to decrypt the secret, especially when using a customer-managed key.

How to eliminate wrong answers

Option A is wrong because API Gateway caching is unrelated to Lambda's ability to access Secrets Manager; caching affects API responses, not secret retrieval permissions. Option C is wrong because the number of VPC subnets (three) is irrelevant to secret rotation access; Lambda requires at least one subnet per AZ for VPC connectivity, but this does not cause AccessDeniedException from Secrets Manager. Option D is wrong because CloudFront invalidation is a CDN cache-clearing mechanism and has no bearing on Lambda's IAM permissions or secret access.

188
MCQhard

A developer is building an application that needs to read a secret API key from AWS Secrets Manager. The application runs on an EC2 instance that is part of an Auto Scaling group. The developer wants to ensure that only this application can retrieve the secret. Which set of steps should the developer take?

A.Store the secret in Secrets Manager, create an IAM user with a policy to read the secret, and embed the user's credentials in the application code
B.Store the secret in Secrets Manager, attach an IAM role to the EC2 instance that grants permission to read the secret, and configure the application to retrieve the secret using the AWS SDK
C.Store the secret as an environment variable in the EC2 user data
D.Store the secret in a configuration file on the instance and restrict file permissions
AnswerB

This is the recommended secure pattern for accessing AWS services from EC2 instances. By attaching an IAM role to the EC2 instance, the application running on it can assume the role's permissions through the instance profile, obtaining temporary, automatically rotated credentials. The AWS SDK then transparently handles the retrieval and refresh of these credentials, eliminating the need to store any static credentials on the instance or in code, thereby adhering to the principle of least privilege and enhancing security posture.

Why this answer

It follows the principle of least privilege and uses IAM roles, which are the secure and recommended way to grant EC2 instances permissions to access AWS Secrets Manager. By attaching an IAM role to the EC2 instance, the application can securely retrieve the secret using the AWS SDK without embedding long-term credentials in code or configuration files. This ensures that only instances with that role can read the secret, and the credentials are automatically rotated by AWS.

Exam trap

The trap here is that candidates may think storing secrets in user data or configuration files is acceptable for simplicity, but the exam emphasizes secure, managed solutions like IAM roles and Secrets Manager to avoid hardcoding credentials and to enable automatic rotation.

How to eliminate wrong answers

Option A is wrong because embedding IAM user credentials in application code is a security anti-pattern; it exposes long-term static credentials that can be compromised and are difficult to rotate. Option C is wrong because storing the secret in EC2 user data is insecure; user data is visible to anyone who can describe the instance or view the console, and it does not provide access control or audit logging. Option D is wrong because storing the secret in a configuration file on the instance, even with restricted file permissions, does not protect against unauthorized access if the instance is compromised, and it lacks centralized management and rotation capabilities.

189
MCQhard

A company has an S3 bucket with a policy that denies access to all users. The bucket owner wants to grant read access to a specific IAM user. What must be done?

A.Create a new bucket and copy objects there.
B.Add an Allow statement in the bucket policy for the user.
C.Remove the Deny statement from the bucket policy.
D.Add the user to the bucket ACL with read permission.
AnswerC

Because an explicit Deny overrides every other permission source, the deny statement itself must be removed (or narrowed with a condition excluding the user) before any Allow — whether from IAM policy, bucket policy, or ACL — can actually grant access.

Why this answer

In S3 bucket policies, an explicit Deny always overrides any Allow. Since the bucket policy currently denies access to all users, simply adding an Allow statement for the specific IAM user will not work—the Deny will still take precedence. Therefore, the Deny statement must be removed or modified to exclude that user before an Allow can be effective.

Option C is correct because it addresses the root cause: the explicit Deny must be eliminated to permit any access.

Exam trap

DVA-C02 often tests the misconception that an Allow statement can override an explicit Deny, but AWS policy evaluation always gives Deny precedence.

How to eliminate wrong answers

Option A is wrong because creating a new bucket and copying objects is unnecessary and does not address the policy conflict; it also requires permissions that may be denied by the same policy. Option B is wrong because adding an Allow statement will not override an explicit Deny; AWS evaluates policies with Deny always taking precedence. Option D is wrong because bucket ACLs are legacy access control mechanisms and cannot override an explicit Deny in a bucket policy; ACLs are also limited in scope and do not support the same granularity as policies.

190
MCQhard

A developer attaches the above S3 bucket policy to my-bucket. A user tries to upload an object using HTTP (not HTTPS). What will happen?

A.The upload succeeds because the Deny effect only applies if the condition is true
B.The upload succeeds if the user also has an Allow in another policy
C.The upload is denied
D.The upload succeeds because there is no Allow statement
AnswerC

The bucket policy's Deny statement with a Bool condition on aws:SecureTransport equal to false is specifically designed to block any request not sent over HTTPS; since the upload is over plain HTTP, the condition is satisfied and the request is denied at the S3 service level.

Why this answer

The bucket policy includes a Deny effect for requests where aws:SecureTransport is false (i.e., HTTP). Since the user is uploading via HTTP, the condition is true, so the Deny statement applies and the upload is denied. Explicit Deny always overrides any Allow.

Exam trap

DVA-C02 often tests the misconception that an Allow in another policy can override an explicit Deny, when in fact explicit Deny always wins.

How to eliminate wrong answers

Option A is wrong because the Deny effect applies when the condition is true; here the condition (SecureTransport false) is true, so the Deny takes effect. Option B is wrong because an explicit Deny in any policy overrides any Allow in another policy. Option D is wrong because the presence of a Deny statement is sufficient to block the action; an Allow statement is not required for the Deny to be effective.

191
MCQmedium

A company hosts a web application on EC2 instances behind an ALB. The application uses cookies to track user sessions. The security team is concerned about session hijacking. Which action should be taken to protect the cookies?

A.Enable encryption on the ALB using a custom SSL certificate.
B.Store session data in ElastiCache instead of cookies.
C.Set the Secure and HttpOnly flags on the session cookie.
D.Use AWS WAF to block requests without a valid session cookie.
AnswerC

Setting the `Secure` flag ensures that the browser will only send the session cookie over encrypted HTTPS connections, preventing its transmission over insecure HTTP and protecting against passive network eavesdropping. The `HttpOnly` flag prevents client-side scripts, such as JavaScript, from accessing the cookie's value. This is a critical defense against Cross-Site Scripting (XSS) attacks, where an attacker might otherwise inject malicious scripts to steal session cookies and hijack user sessions.

Why this answer

Setting the Secure and HttpOnly flags on the session cookie is the correct action because the Secure flag ensures the cookie is only sent over HTTPS, preventing interception via man-in-the-middle attacks, while the HttpOnly flag prevents client-side scripts (e.g., JavaScript) from accessing the cookie, mitigating cross-site scripting (XSS)-based session hijacking. This directly addresses the security team's concern by hardening the cookie against common attack vectors without requiring architectural changes.

Exam trap

The trap here is that candidates often confuse encryption of the connection (Option A) with securing the cookie itself, or they assume moving session state server-side (Option B) eliminates the need for cookie security flags, when in fact the session identifier cookie still requires Secure and HttpOnly protection.

How to eliminate wrong answers

Option A is wrong because enabling encryption on the ALB with a custom SSL certificate protects data in transit between the client and ALB, but it does not secure the cookie itself from being read by JavaScript or transmitted over non-HTTPS connections if the application sets the cookie without the Secure flag. Option B is wrong because storing session data in ElastiCache instead of cookies changes where session state is stored (server-side vs. client-side), but it does not inherently protect the session identifier cookie from hijacking; the cookie still needs Secure and HttpOnly flags to prevent interception and script access. Option D is wrong because AWS WAF can block requests based on rules, but it cannot validate the integrity or security attributes of a session cookie; it would only filter based on presence or content, not prevent hijacking if the cookie is already stolen.

192
MCQhard

A Lambda function in a VPC must retrieve secrets from Secrets Manager without traversing the public internet. Which configuration should be used?

A.A public NAT gateway only
B.An internet gateway attached to the Lambda subnet
C.A VPC peering connection to every AWS region
D.An interface VPC endpoint for Secrets Manager with appropriate security groups
AnswerD

An interface VPC endpoint for Secrets Manager, powered by AWS PrivateLink, establishes a private connection from your VPC to the Secrets Manager service. This allows the Lambda function to retrieve secrets without traffic leaving the Amazon network or traversing the public internet, significantly enhancing security and reducing latency. Configuring appropriate security groups on the endpoint ensures only authorized resources, like the Lambda function, can establish connections.

Why this answer

An interface VPC endpoint (AWS PrivateLink) for Secrets Manager allows Lambda functions within a VPC to securely retrieve secrets using private IP addresses, without traversing the public internet. This is achieved by creating an elastic network interface in the VPC subnet with a security group that controls access, ensuring traffic stays within the AWS network.

Exam trap

The trap here is that candidates often confuse NAT gateways or internet gateways as solutions for private service access, not realizing that AWS PrivateLink endpoints are the correct mechanism to keep traffic within the AWS backbone.

How to eliminate wrong answers

Option A is wrong because a public NAT gateway enables outbound internet access from private subnets but does not provide a private path to Secrets Manager; traffic would still traverse the internet. Option B is wrong because an internet gateway attached to the Lambda subnet would expose the Lambda function to the public internet, defeating the requirement to avoid public internet traversal and introducing security risks. Option C is wrong because VPC peering connections connect VPCs within the same or different regions but do not provide access to AWS services like Secrets Manager; they are used for inter-VPC communication, not service endpoints.

193
MCQeasy

A developer needs to grant cross-account access to an S3 bucket owned by Account A to a user in Account B. Which approach is the most secure?

A.Create an IAM role in Account A with a trust policy allowing the user from Account B to assume it.
B.Share the access keys of an IAM user in Account A with the user in Account B.
C.Add a bucket policy in Account A that grants access to the user in Account B, and attach an IAM policy to the user in Account B allowing the S3 actions.
D.Attach an IAM policy to the user in Account B that grants access to the S3 bucket.
AnswerC

This is the most secure and recommended method for granting cross-account S3 access, adhering to the principle of least privilege. The bucket policy in Account A, a resource-based policy, explicitly grants permission to the specific IAM user (or role) in Account B to perform defined S3 actions on the bucket. Concurrently, an identity-based IAM policy attached to the user in Account B explicitly allows that user to perform those same S3 actions. Both policies must grant the necessary permissions for access to be successful, creating a robust and auditable access control mechanism.

Why this answer

The most secure because it combines a resource-based bucket policy in Account A that explicitly grants access to the user in Account B with an identity-based IAM policy attached to that user in Account B. This dual-policy approach ensures that the user can only access the bucket when both policies allow the action, following the principle of least privilege and avoiding the need to share long-term credentials.

Exam trap

The trap here is that candidates often assume an IAM policy in the target account alone is sufficient for cross-account S3 access, forgetting that the owning account must explicitly allow the access via a resource-based policy like a bucket policy.

How to eliminate wrong answers

Option A is wrong because creating an IAM role in Account A with a trust policy for the user in Account B would require the user to assume the role, which is a valid cross-account access method but is less direct and adds unnecessary complexity for simple S3 bucket access; it is not the most secure or straightforward approach for this specific scenario. Option B is wrong because sharing access keys of an IAM user in Account A with a user in Account B violates security best practices by exposing long-term credentials, increasing the risk of credential leakage and unauthorized access. Option D is wrong because attaching an IAM policy to the user in Account B alone cannot grant access to an S3 bucket in Account A; cross-account access requires a resource-based policy (bucket policy or ACL) in the owning account to explicitly allow the external user.

194
MCQmedium

A company has an S3 bucket that stores log files. The bucket policy grants the AWSServiceRoleForSSO service role write access. However, the logs are not being written. What is the MOST likely reason?

A.The bucket has S3 Block Public Access enabled, which blocks all service role access.
B.The bucket policy uses a service role ARN that is not a valid principal for S3 bucket policies.
C.The bucket ACL is set to private, which prevents service role writes.
D.The bucket has default encryption enabled using SSE-S3, which prevents writes from service roles.
AnswerB

S3 bucket policies require a valid principal to define who can perform actions on the bucket. While IAM roles are principals, a service role's ARN itself is typically not the correct principal to specify directly in an S3 bucket policy when granting permissions to an AWS service. Instead, the *service principal* for the AWS service (e.g., `logs.amazonaws.com` for CloudWatch Logs, or `s3.amazonaws.com` for S3 itself) should be used to allow the service to write to the bucket on behalf of its users or internal processes. This distinction is crucial for proper cross-service authorization.

Why this answer

The bucket policy uses the ARN of the AWSServiceRoleForSSO service-linked role as the principal, but S3 bucket policies do not accept service role ARNs as valid principals. Instead, you must use the AWS service principal (e.g., sso.amazonaws.com) when granting permissions to an AWS service that uses a service role. Therefore, the policy fails to grant write access.

Options A, C, and D are incorrect: S3 Block Public Access settings only block public access, not access from service roles; bucket ACLs are not effective when a bucket policy exists and private ACLs do not prevent authorized writes; default encryption with SSE-S3 does not block writes from any principal.

195
MCQhard

A developer is using AWS Secrets Manager to rotate database credentials automatically. The rotation fails with the error 'The secret value is not valid JSON.' What is the most likely cause?

A.The secret is in a different AWS region than the Lambda rotation function.
B.The secret value was stored as a plain string instead of a JSON object.
C.The secret name is not base64-encoded.
D.The secret does not have the correct version label.
AnswerB

AWS Secrets Manager automatic rotation functions, typically implemented as Lambda functions, are designed to parse specific key-value pairs from the secret string to perform database credential updates. When a secret value is stored as a plain string, such as 'myPassword123', the Lambda function cannot extract required components like 'username', 'password', 'host', or 'port' because the expected JSON structure is absent. This lack of structured data prevents the rotation function from successfully connecting to the database and updating the credentials, leading to a rotation failure.

Why this answer

AWS Secrets Manager requires secret values to be stored as valid JSON objects when automatic rotation is configured. If the secret is stored as a plain string (e.g., a single password string without key-value pairs), the rotation function cannot parse it, resulting in the 'The secret value is not valid JSON' error. This is because the Lambda rotation function expects to read and write a JSON structure to manage the credentials during rotation.

Exam trap

The trap here is that candidates may confuse the JSON validation error with other rotation failures, such as network issues or permission errors, but the specific error message 'The secret value is not valid JSON' directly points to the secret's format being incorrect.

How to eliminate wrong answers

Option A is wrong because the Lambda rotation function and the secret must be in the same AWS region; cross-region rotation is not supported, but this would cause a different error (e.g., 'AccessDenied' or 'ResourceNotFoundException'), not a JSON parsing error. Option C is wrong because secret names are not required to be base64-encoded; they are plain text strings that identify the secret, and base64 encoding is irrelevant to JSON validity. Option D is wrong because version labels (e.g., AWSCURRENT, AWSPREVIOUS) are managed automatically by Secrets Manager during rotation; an incorrect version label would cause a versioning error, not a JSON parsing failure.

196
MCQeasy

A developer runs an application on Amazon EC2 that needs to securely store database credentials (username and password). The security team requires that the credentials be automatically rotated every 30 days. Which AWS service should the developer use to store and automatically rotate the credentials?

A.AWS Systems Manager Parameter Store with a SecureString parameter.
B.AWS Secrets Manager with automatic rotation enabled.
C.AWS Identity and Access Management (IAM) roles for EC2.
D.AWS Key Management Service (KMS) to store the credentials as encrypted data.
AnswerB

AWS Secrets Manager is purpose-built for managing, retrieving, and rotating database credentials, API keys, and other secrets throughout their lifecycle. Its key differentiator is native automatic rotation, which can be configured on a schedule (e.g., every 30 days) for various supported services, including Amazon RDS, Redshift, and even custom secrets via Lambda functions. This built-in capability eliminates the need for manual rotation or custom code, significantly enhancing security posture and operational efficiency.

Why this answer

AWS Secrets Manager is designed specifically for managing secrets such as database credentials, with built-in capabilities for automatic rotation according to a schedule (e.g., every 30 days). It integrates natively with supported databases (e.g., Amazon RDS, Redshift, DocumentDB) to rotate credentials without custom code, and it encrypts secrets at rest using AWS KMS. This makes it the correct choice for the developer's requirement of secure storage and automated rotation.

Exam trap

The trap here is that candidates often confuse Parameter Store's SecureString (which can store encrypted secrets but lacks built-in rotation) with Secrets Manager, overlooking the explicit requirement for automatic rotation.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Parameter Store with a SecureString parameter can store encrypted credentials but does not support automatic rotation of the secret value; rotation would require custom automation via AWS Lambda or other services. Option C is wrong because IAM roles for EC2 provide temporary credentials for AWS API access, not for storing or rotating database credentials (username/password); they cannot be used to store secrets. Option D is wrong because AWS KMS is a key management service for encryption keys, not a secret storage service; it cannot store credentials or perform rotation.

197
MCQhard

A developer is troubleshooting access to an Amazon S3 bucket. The bucket policy allows access to the developer's IAM role, but the developer receives an Access Denied error when trying to upload objects. The developer is using an IAM user with access keys for API calls. What is the most likely cause?

A.The developer’s IAM user does not have s3:PutObject permission
B.The bucket policy does not include a Principal element
C.The S3 bucket is in a different region from the developer's API endpoint
D.The bucket policy allows the role ARN, but the developer is using user credentials
AnswerD

This is the most direct cause for an Access Denied error in this scenario. If an S3 bucket policy is configured to grant permissions specifically to an IAM Role's Amazon Resource Name (ARN), but the developer is making the request directly with their personal IAM User credentials, the bucket policy will not recognize the user as the authorized principal. The IAM User and the IAM Role are distinct identities; therefore, the bucket policy's permissions, which are scoped to the role, will not apply to the user, resulting in access being denied.

Why this answer

The bucket policy grants access to the developer's IAM role ARN, but the developer is authenticating as an IAM user with access keys. IAM roles and IAM users are distinct principals, so the role-based grant in the bucket policy does not apply to the user's credentials, resulting in Access Denied. The fix is either to assume the role or to add the IAM user ARN to the bucket policy.

Exam trap

DVA-C02 often tests the confusion between IAM users and IAM roles as principals, tricking candidates into picking permission-related answers when the real issue is identity mismatch.

How to eliminate wrong answers

Option A is wrong because the question states the bucket policy allows access to the role — the issue is principal mismatch, not missing s3:PutObject permission on the user (though that could also cause denial, it is not the most likely cause given the scenario). Option B is wrong because a bucket policy without a Principal element is only valid in specific cases (e.g., when the bucket owner is the same account and the policy is used with IAM evaluation); the scenario implies a Principal is present since it references a role ARN. Option C is wrong because S3 is a global service with regional endpoints that all work regardless of the caller's region; cross-region API calls succeed as long as the endpoint is valid.

198
MCQmedium

A developer is building a serverless application using API Gateway and Lambda. The API must be accessible only from a specific VPC. How can the developer achieve this?

A.Use security groups to restrict access to the API Gateway.
B.Create the API Gateway inside the VPC.
C.Use CloudFront with an origin access identity to restrict access.
D.Create a VPC endpoint for API Gateway and attach a resource policy to the API that allows access only from the VPC endpoint.
AnswerD

Creating an interface VPC endpoint for API Gateway establishes a private connection from your VPC to the API Gateway service, allowing clients within the VPC to access the API without traversing the public internet. Concurrently, an API Gateway resource policy can be configured to explicitly deny all requests that do not originate from this specific VPC endpoint. This combination ensures that the API is exclusively accessible from within the designated VPC, providing robust network-level isolation.

Why this answer

To restrict an API Gateway REST API to a specific VPC, the correct pattern is a VPC endpoint (interface endpoint) for API Gateway combined with a resource policy on the API that allows only that endpoint. The resource policy uses aws:sourceVpce to whitelist the endpoint, and clients inside the VPC reach the API via the private DNS name of the endpoint. This is the documented AWS approach for private API access.

Exam trap

The trap is assuming API Gateway can be placed inside a VPC or protected by security groups like EC2 — candidates miss that PrivateLink VPC endpoints plus resource policies are the only supported mechanism for VPC-scoped API access.

How to eliminate wrong answers

Option A is wrong because API Gateway is a managed regional service outside the customer VPC — security groups cannot be attached to it to gate inbound API traffic. Option B is wrong because API Gateway cannot be deployed 'inside' a VPC; only the VPC endpoint (ENI) lives in the VPC. Option C is wrong because CloudFront with an OAI restricts access to S3 origins, not to API Gateway, and does not limit access to a specific VPC.

199
MCQeasy

A developer needs to grant an IAM user the ability to create and manage EC2 instances, but only in the us-east-1 region. Which IAM policy statement should be used?

A.{"Effect": "Allow", "Action": "ec2:*", "Resource": "*", "Condition": {"StringEquals": {"ec2:Region": "us-east-1"}}}
B.{"Effect": "Allow", "Action": "ec2:Describe*", "Resource": "*"}
C.{"Effect": "Allow", "Action": "ec2:*", "Resource": "arn:aws:ec2:us-east-1:*:*"}
D.{"Effect": "Allow", "Action": "ec2:*", "Resource": "*"}
AnswerA

This policy grants full ec2:* permissions but attaches a Condition block that checks the ec2:Region condition key against 'us-east-1'. Because ec2:Region is populated by AWS on every EC2 API call based on the endpoint's region, this condition reliably scopes the allowed actions to that one region regardless of which resource ARN is targeted.

Why this answer

The Condition element with ec2:Region restricts the allowed actions to only the us-east-1 region, while allowing all EC2 actions (ec2:*). Option B is incorrect because it only permits Describe actions, not creating or managing instances. Option C is incorrect because although the Resource ARN includes the region, the ec2:* actions do not support resource-level restrictions with region in the ARN in the same way; a Condition is needed.

Option D is incorrect because it allows EC2 actions in all regions with no restriction.

200
Multi-Selecteasy

A developer is tasked with encrypting data at rest for an Amazon RDS for MySQL database. The developer wants to use AWS KMS for key management. Which TWO configurations are valid? (Choose TWO.)

Select 2 answers
A.Create a customer managed KMS key and specify it when creating the DB instance.
B.Enable encryption after the DB instance is created by modifying the DB instance.
C.Enable encryption using the default AWS managed key for RDS.
D.Use S3 server-side encryption (SSE-S3) with the RDS instance.
E.Use an AWS owned KMS key for encryption.
AnswersA, C

Creating a customer managed key (CMK) in AWS Key Management Service (KMS) allows a developer to maintain full control over the encryption key's policy, rotation schedule, and access permissions. When creating an Amazon RDS DB instance, this CMK can be explicitly specified, ensuring that all data at rest, including the underlying EBS volumes and subsequent snapshots, is encrypted using a key managed by the customer. This approach provides enhanced compliance and auditing capabilities.

Why this answer

You can create a customer managed KMS key and specify it when creating the DB instance. Amazon RDS for MySQL supports encryption at rest using AWS KMS, and you can choose a customer managed key at launch time. This key is used to encrypt the DB instance's storage, automated backups, read replicas, and snapshots.

Exam trap

The trap here is that candidates may think encryption can be toggled on after creation (Option B) or that AWS owned keys are a valid choice for RDS (Option E), but AWS explicitly requires encryption to be set at launch and only supports AWS managed or customer managed keys for RDS.

201
MCQhard

A developer is using AWS Lambda to process files uploaded to an S3 bucket. The Lambda function needs to write logs to CloudWatch Logs. Which of the following is required to allow this?

A.Attach an IAM policy to the Lambda execution role with CloudWatch Logs permissions
B.Add a resource-based policy to the Lambda function
C.Configure the S3 bucket to trigger Lambda, and Lambda automatically logs to CloudWatch
D.Create an IAM role for CloudWatch Logs and assign it to the Lambda function
AnswerA

Attaching an IAM policy with CloudWatch Logs permissions to the Lambda execution role is the correct approach. The Lambda execution role defines the permissions that the function itself has when interacting with other AWS services. For a Lambda function to successfully send its logs (e.g., from `console.log` or `print` statements) to CloudWatch Logs, this role must explicitly grant actions like `logs:CreateLogGroup`, `logs:CreateLogStream`, and `logs:PutLogEvents` to the relevant CloudWatch Logs resources.

Why this answer

The Lambda execution role is the IAM role that Lambda assumes when the function runs, and it defines what AWS services and resources the function can access. To write logs to CloudWatch Logs, the execution role must have an IAM policy attached that grants permissions for actions like logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents. Without these permissions, the function cannot write logs, even if it has the necessary code.

Therefore, attaching an IAM policy to the Lambda execution role with CloudWatch Logs permissions is required.

Exam trap

DVA-C02 often tests the misconception that Lambda automatically has permissions to write to CloudWatch Logs or that a separate role for CloudWatch Logs is needed, when in fact the execution role must be explicitly granted those permissions.

How to eliminate wrong answers

Option B is wrong because a resource-based policy on a Lambda function controls who can invoke the function (e.g., other AWS accounts or services), not what the function can access; it does not grant the function permissions to write to CloudWatch Logs. Option C is wrong because configuring an S3 bucket to trigger Lambda does not automatically grant logging permissions; the execution role must still have explicit CloudWatch Logs permissions, and Lambda does not automatically log to CloudWatch without them. Option D is wrong because creating an IAM role for CloudWatch Logs and assigning it to the Lambda function is not how permissions work; the Lambda function assumes its execution role, and that role must have policies that allow CloudWatch Logs actions, not a separate role for CloudWatch Logs.

202
MCQmedium

A company is using AWS CodePipeline to deploy a web application. The pipeline must securely store and use database credentials. Which AWS service should the developer use to store the credentials and retrieve them during deployment?

A.IAM role attached to the CodePipeline service role.
B.AWS Secrets Manager.
C.AWS Systems Manager Parameter Store with a SecureString parameter.
D.Amazon DynamoDB with server-side encryption.
AnswerB

AWS Secrets Manager is purpose-built for securely storing, managing, and rotating sensitive credentials such as database passwords, API keys, and other secrets. It integrates directly with various AWS services, including CodePipeline, and offers automatic rotation capabilities for many database types, enhancing security by regularly changing credentials without manual intervention. This service provides robust encryption at rest and in transit, fine-grained access control, and auditability through AWS CloudTrail, making it the most appropriate choice for this use case.

Why this answer

AWS Secrets Manager is purpose-built for storing, rotating, and retrieving sensitive credentials like database passwords. It integrates natively with CodePipeline/CodeBuild via the AWS CLI or SDK, supports automatic rotation via Lambda, and provides fine-grained IAM access control and encryption with KMS. This makes it the correct choice for securely storing and retrieving database credentials during deployment.

Exam trap

DVA-C02 often tests the Secrets Manager vs. Parameter Store distinction — candidates pick Parameter Store SecureString for credentials, missing that Secrets Manager is the AWS-recommended service when rotation and credential lifecycle management are required.

How to eliminate wrong answers

Option A is wrong because an IAM role grants permissions but does not store credentials — it cannot hold a database password. Option C is wrong because Systems Manager Parameter Store with SecureString can store secrets, but it lacks native rotation and is better suited for configuration values; Secrets Manager is the AWS-recommended service for credentials requiring rotation. Option D is wrong because DynamoDB is a NoSQL database, not a secrets store — using it for credentials requires custom encryption, access control, and rotation logic, which is an anti-pattern.

203
MCQeasy

A company wants to encrypt data at rest in an S3 bucket using server-side encryption. Which option provides the MOST control over the encryption key?

A.SSE-KMS (AWS KMS keys)
B.SSE-C (customer-provided keys)
C.Client-side encryption
D.SSE-S3 (S3-managed keys)
AnswerB

SSE-C (Server-Side Encryption with Customer-Provided Keys) mandates that the customer supply their unique encryption key with every PUT and GET request to S3. Amazon S3 uses this key solely for encrypting or decrypting the object data and then immediately discards it, never storing the key itself. This method provides the highest level of customer control over the encryption key's generation, storage, rotation, and lifecycle, as AWS never retains custody of the key.

Why this answer

SSE-C (customer-provided keys) gives you the most control because you manage the encryption key yourself—you provide the key in each request, and AWS discards it after use. This means you have full lifecycle control over the key material, including rotation, deletion, and access policies, without AWS ever storing the key. In contrast, SSE-KMS and SSE-S3 rely on AWS-managed or AWS-controlled key stores, reducing your direct control.

Exam trap

The trap here is that candidates confuse 'most control' with 'easiest management' and pick SSE-KMS, but the question explicitly asks for the option that provides the MOST control over the encryption key, which is SSE-C because you own and manage the key entirely.

How to eliminate wrong answers

Option A is wrong because SSE-KMS uses AWS KMS keys, where AWS manages the key store and you share control with AWS via key policies and grants, so you do not have the most control. Option C is wrong because client-side encryption encrypts data before sending it to S3, which gives you full control over the key, but the question specifically asks about server-side encryption, so this is out of scope. Option D is wrong because SSE-S3 uses S3-managed keys (AES-256) where AWS fully manages the key lifecycle, giving you the least control over the encryption key.

204
MCQmedium

A developer is deploying an application with AWS CodeDeploy. The application needs to access a database password. Which service should be used to securely store and retrieve the password?

A.AWS Systems Manager Parameter Store
B.AWS CloudFormation template parameters
C.Amazon DynamoDB with encryption at rest
D.AWS Secrets Manager
AnswerD

AWS Secrets Manager is purpose-built for securely storing, managing, and retrieving secrets throughout their lifecycle, making it the optimal choice for applications. It natively supports automatic rotation for various types of credentials, including database passwords (e.g., RDS, Redshift, DocumentDB) and API keys, significantly enhancing security by regularly changing secrets without requiring application code changes. Furthermore, it provides fine-grained access control, auditing capabilities, and seamless integration with other AWS services like CodeDeploy and Lambda for secure secret injection and retrieval.

Why this answer

AWS Secrets Manager is designed specifically for securely storing, rotating, and retrieving secrets such as database passwords, API keys, and tokens. It integrates natively with AWS services like RDS and provides fine-grained access control via IAM. CodeDeploy deployments can retrieve secrets at runtime using the Secrets Manager API or SDK.

Exam trap

DVA-C02 often tests whether candidates choose Parameter Store over Secrets Manager for database passwords; while Parameter Store can store secure strings, Secrets Manager is the correct answer when rotation and native integration are required.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Parameter Store can store secure strings, but it lacks native rotation and is less specialized for secrets management; Secrets Manager is the preferred service for database passwords. Option B is wrong because CloudFormation template parameters are for input values at stack creation and are not secure storage for secrets; they can be visible in logs and templates. Option C is wrong because DynamoDB with encryption at rest is a database, not a secrets management service; storing passwords there requires custom encryption and access controls.

205
MCQhard

A developer is designing a multi-tier application. The web tier must be accessible from the internet, while the application tier should only be accessible from the web tier. Which security group configuration meets these requirements?

A.Web tier SG allows inbound from application tier SG.
B.Web tier SG allows inbound 0.0.0.0/0 on port 80; Application tier SG allows inbound from web tier SG on port 8080.
C.Both SGs allow inbound 0.0.0.0/0 on necessary ports.
D.Web tier SG allows inbound 0.0.0.0/0 on port 80; Application tier SG allows inbound from 0.0.0.0/0 on port 443.
AnswerB

This correctly layers access: the web tier's security group permits inbound traffic from any source (0.0.0.0/0) on the public-facing port, while the application tier's security group references the web tier's security group ID as its only allowed inbound source, so app-tier instances are reachable exclusively from web-tier instances.

Why this answer

Application tier security group should allow inbound traffic only from the web tier security group, not from the internet or CIDR ranges.

206
MCQhard

A developer is troubleshooting an IAM policy that is not working as expected. The policy has an Allow effect for s3:PutObject but the user gets AccessDenied. The user also has a Deny policy attached. What is the most likely reason?

A.The resource-based policy on S3 denies access
B.The Allow policy is evaluated before the Deny policy
C.An explicit Deny in an IAM policy overrides the Allow
D.An SCP denies the action
AnswerC

This statement accurately reflects a core principle of AWS IAM policy evaluation. If an IAM policy contains an explicit Deny statement for a specific action on a resource, that Deny will always override any Allow statements that might exist in the same policy, other identity-based policies, or even resource-based policies. An explicit Deny acts as an absolute prohibition, ensuring that access is blocked even if multiple Allow statements are present.

Why this answer

AWS IAM evaluates all policies (identity-based, resource-based, and SCPs) and an explicit Deny always overrides any Allow, regardless of the order in which the policies are written. In this scenario, even though the user has an Allow effect for s3:PutObject, the attached Deny policy explicitly denies the action, resulting in an AccessDenied error. This is a fundamental rule of AWS authorization logic: an explicit Deny cannot be overridden by any Allow.

Exam trap

The trap here is that candidates often assume the order of policy evaluation (Allow before Deny) matters, but AWS explicitly states that an explicit Deny overrides any Allow, making the order irrelevant.

How to eliminate wrong answers

Option A is wrong because a resource-based policy on S3 that denies access would also cause AccessDenied, but the question states the user has a Deny policy attached, making the explicit Deny in the IAM policy the most likely reason. Option B is wrong because AWS evaluates all policies in a single pass, and the order of evaluation (Allow before Deny) does not matter; the explicit Deny always takes precedence. Option D is wrong because while an SCP could deny the action, the question specifically mentions the user has a Deny policy attached, and SCPs apply at the account or OU level, not directly to the user; the most direct cause is the attached Deny policy.

207
MCQeasy

A developer is using AWS Certificate Manager (ACM) to provision an SSL/TLS certificate for a website hosted on CloudFront. The certificate must be renewed automatically. What is the correct action?

A.The developer must configure a Lambda function to renew the certificate.
B.The certificate cannot be used with CloudFront; ACM certificates are only for ALB.
C.ACM automatically renews the certificate if it uses DNS validation.
D.The developer must manually request a new certificate before expiration.
AnswerC

This statement is correct. AWS Certificate Manager (ACM) automatically attempts to renew certificates that were issued using DNS validation, typically starting 60 days before expiration. For this automatic renewal to succeed, the CNAME record created during the initial validation must remain in the DNS configuration, allowing ACM to re-validate domain ownership without any manual intervention from the developer.

Why this answer

ACM automatically renews certificates that use DNS validation, provided the required DNS CNAME record remains in place. CloudFront supports ACM certificates in us-east-1, and ACM handles renewal without any manual intervention or additional infrastructure like Lambda functions.

Exam trap

The trap here is that candidates assume ACM requires manual renewal or additional automation (like Lambda), but ACM's automatic renewal for DNS-validated certificates is a key managed feature tested in the DVA-C02 exam.

How to eliminate wrong answers

Option A is wrong because ACM automatically manages renewal for DNS-validated certificates; a Lambda function is unnecessary and not part of the renewal process. Option B is wrong because ACM certificates are fully supported with CloudFront (when issued in us-east-1), not limited to ALB. Option D is wrong because ACM handles automatic renewal for eligible certificates; manual re-request is only needed if validation fails or the certificate is not eligible.

208
MCQeasy

A developer needs to grant cross-account access to an Amazon S3 bucket. The developer's AWS account (Account A) owns the bucket, and a user in another account (Account B) needs to write objects to it. The developer has already added a bucket policy that grants the user in Account B permissions. What additional step is required?

A.No additional steps are needed; the bucket policy alone is sufficient.
B.The administrator of Account B must attach an IAM policy to the user that allows the required S3 actions.
C.Create a new IAM role in Account B and have the user assume the role.
D.Enable S3 ACLs on the bucket and grant write access to the Account B user.
AnswerB

To successfully grant cross-account S3 access, the administrator of Account B must attach an IAM policy to the specific user or role that will be accessing the bucket. This identity-based policy explicitly authorizes the principal within Account B to perform the desired S3 actions, such as s3:PutObject, on the target bucket in Account A. This policy works in conjunction with the resource-based bucket policy in Account A, which grants permissions to Account B's principal, ensuring that both sides of the trust relationship are established for successful access.

Why this answer

Cross-account access to S3 requires both a resource-based policy (the bucket policy in Account A) and a user-based policy (an IAM identity-based policy in Account B). The bucket policy grants permissions to the Account B user, but that user cannot perform actions unless their own account explicitly allows those actions via an IAM policy. Without this, the request is denied by the user's own account's implicit deny, even if the bucket policy permits it.

Exam trap

The trap here is that candidates often assume a bucket policy alone is enough for cross-account access, forgetting that the requesting user's account must also explicitly authorize the action via an IAM policy.

How to eliminate wrong answers

Option A is wrong because a bucket policy alone is insufficient for cross-account access; the user in Account B must also have an IAM policy that allows the S3 actions, as the user's account must explicitly authorize the request. Option C is wrong because creating an IAM role in Account B and having the user assume it is an alternative approach, but it is not required; the question asks for the additional step given that a bucket policy is already in place, and the simplest correct step is to attach an IAM policy to the user, not to create a role. Option D is wrong because S3 ACLs are legacy and not recommended; more importantly, ACLs grant access to AWS accounts or canonical user IDs, not to specific IAM users, and enabling ACLs does not replace the need for an IAM policy in Account B.

209
MCQhard

A company uses AWS KMS with customer managed keys to encrypt S3 objects. The security team requires automatic key rotation. What must the developer do to enable rotation?

A.Use AWS managed keys instead of customer managed keys
B.Rotation is enabled by default for all KMS keys
C.Enable automatic key rotation in the KMS key settings
D.Create a new key and update the alias to point to the new key annually
AnswerC

For Customer Managed Keys (CMKs), automatic key rotation is an opt-in feature that can be enabled directly within the AWS KMS console or via API calls. Enabling this setting instructs KMS to generate new cryptographic material for the key annually, while retaining the same key ID and ARN. This ensures that data encrypted with the key remains accessible without needing re-encryption, fulfilling the requirement for automatic rotation.

Why this answer

Customer managed KMS keys support optional automatic key rotation, which must be explicitly enabled in the key's settings. Once enabled, AWS rotates the backing key material every 365 days (or a custom period of 90–2560 days) while preserving the same key ID, ARN, and alias, so existing ciphertext remains decryptable. Enabling rotation in the KMS key settings is therefore the correct action.

Exam trap

DVA-C02 often tests the misconception that KMS rotation is on by default or that AWS managed keys give you configurable rotation — candidates must remember rotation is opt-in only for customer managed keys.

How to eliminate wrong answers

Option A is wrong because switching to AWS managed keys does not satisfy the requirement to control rotation on customer managed keys and AWS managed keys rotate on an AWS-defined schedule you cannot configure. Option B is wrong because automatic rotation is NOT enabled by default for customer managed keys — it is opt-in, and asymmetric keys, HMAC keys, and keys in custom key stores do not support it. Option D is wrong because manually creating a new key and repointing the alias is manual rotation, not automatic rotation, and it requires re-encrypting existing data since the new key has a different key ID.

210
MCQhard

A developer is building a serverless order-processing application. An AWS Lambda function must read records from an Amazon DynamoDB table and write audit entries to an Amazon SQS queue. The developer creates the Lambda execution role and attaches a managed policy that grants dynamodb:GetItem, dynamodb:PutItem, sqs:SendMessage, and logs:CreateLogGroup permissions on the specific resources. After deployment, the Lambda function successfully reads and writes to DynamoDB, but every attempt to send a message to the SQS queue fails with an AccessDenied error. The developer confirms the SQS queue URL in the code is correct and the queue exists in the same AWS Region. Which action will resolve this issue with the LEAST privilege?

A.Add a resource-based policy to the SQS queue that allows the Lambda execution role to call sqs:SendMessage.
B.Enable AWS CloudTrail data events for the SQS queue and retry the Lambda invocation.
C.Attach the AmazonSQSFullAccess managed policy to the Lambda execution role.
D.Update the Lambda execution role's identity-based policy to use the SQS queue's ARN as the Resource for the sqs:SendMessage statement.
AnswerD

The execution role's policy must specify the correct ARN of the target SQS queue as the Resource for the sqs:SendMessage action. If the Resource was written incorrectly, for example using the queue URL or a different queue's ARN, the action is implicitly denied. Correcting the Resource to match the queue ARN grants only the required permission on the intended queue, satisfying least privilege while resolving the AccessDenied error.

Why this answer

The Lambda execution role already includes the sqs:SendMessage action, so the denial is caused by the Resource element not matching the target queue's ARN. AWS evaluates identity-based policies by matching the requested resource against the Resource element; a mismatch results in an implicit deny. Correcting the Resource to the queue's ARN grants exactly the needed permission on the intended queue, which resolves the error while honoring least privilege.

Exam trap

The trap here is assuming that any AccessDenied error means the action is missing from the policy, when in fact the action is present but scoped to the wrong resource ARN.

211
MCQeasy

A developer needs to allow a user to deploy AWS CloudFormation stacks but restrict the user from creating or modifying IAM resources. Which IAM policy should the developer attach to the user?

A.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"cloudformation:*","Resource":"*"},{"Effect":"Deny","Action":"iam:*","Resource":"*"}]}
B.{"Effect":"Allow","Action":"iam:*","Resource":"*"}
C.{"Effect":"Allow","Action":"cloudformation:*","Resource":"*"}
D.{"Effect":"Deny","Action":"cloudformation:*","Resource":"*"}
AnswerA

This policy combines an Allow on cloudformation:* with an explicit Deny on iam:*. Because an explicit deny always overrides an allow in IAM's evaluation logic, the user can create, update, and delete stacks freely, but any attempt to create, modify, or delete IAM roles, users, or policies — even indirectly through a stack template — is blocked.

Why this answer

It grants full access to CloudFormation actions via an Allow statement while explicitly denying all IAM actions via a Deny statement, ensuring the user can deploy stacks but cannot create or modify IAM resources. Option B is incorrect because it allows all IAM actions, granting excessive permissions. Option C is incorrect because it allows CloudFormation but does not explicitly deny IAM, which could permit IAM actions if other policies allow.

Option D is incorrect because it denies all CloudFormation actions, preventing stack deployment.

212
MCQeasy

A developer needs to allow an EC2 instance to access an S3 bucket securely without storing long-term credentials on the instance. Which AWS service should be used to provide temporary credentials?

A.Create an IAM user with S3 access and store the access key on the EC2 instance.
B.Configure a security group allowing outbound traffic to S3.
C.Attach an IAM role to the EC2 instance profile with S3 permissions.
D.Use an EC2 key pair to encrypt access to S3.
AnswerC

Attaching an IAM role to an EC2 instance profile is the secure and recommended method for granting AWS service access. This mechanism leverages the AWS Security Token Service (STS) to provide temporary, frequently rotated credentials to applications running on the instance. These credentials are automatically managed and retrieved via the EC2 instance metadata service, eliminating the need to embed static access keys.

Why this answer

IAM roles for EC2 allow the instance to assume a role and obtain temporary credentials from STS. Option A is wrong because IAM users have long-term credentials. Option B is wrong because security groups are network firewalls and do not provide credentials.

Option D is wrong because EC2 key pairs are for SSH access, not API credentials.

213
MCQmedium

A company wants to restrict access to an Amazon S3 bucket so that only requests originating from a specific Amazon VPC are allowed. The bucket is in the same AWS account as the VPC. Which configuration should the developer implement?

A.Bucket policy with condition aws:SourceVpc
B.Bucket policy with condition aws:SourceIp
C.Bucket ACL with VPC ID
D.VPC Endpoint policy
AnswerA

The `aws:SourceVpc` condition key within an Amazon S3 bucket policy is the most direct and secure method to restrict access. This condition ensures that requests to the S3 bucket are permitted only if they originate from the specified Virtual Private Cloud (VPC) ID, effectively isolating access to resources within that particular network boundary. It leverages the inherent network context of the request, providing a robust and scalable solution without needing to manage individual IP addresses.

Why this answer

The `aws:SourceVpc` condition key in an S3 bucket policy allows you to restrict access to requests originating from a specific VPC. This works in conjunction with a VPC endpoint for S3 (Gateway or Interface endpoint), which ensures that traffic from the VPC to S3 stays within the AWS network and does not traverse the public internet. The condition evaluates the VPC ID from which the request originates, providing a secure, network-level access control.

Exam trap

The trap here is that candidates often confuse `aws:SourceVpc` with `aws:SourceIp` or think a VPC Endpoint policy alone can restrict bucket access, but the bucket policy is the authoritative mechanism for inbound access control, while the endpoint policy governs outbound permissions from the VPC.

How to eliminate wrong answers

Option B is wrong because `aws:SourceIp` restricts access based on public IP addresses, but requests from a VPC using a VPC endpoint have private IPs and the source IP is not the VPC's public IP, making this condition ineffective for VPC-based access control. Option C is wrong because S3 bucket ACLs do not support VPC IDs; ACLs can only grant access to AWS accounts or predefined groups (e.g., AllUsers, AuthenticatedUsers), not to specific VPCs. Option D is wrong because a VPC Endpoint policy controls what actions principals within the VPC can perform on the S3 service, but it does not restrict access from the bucket's perspective; the bucket policy is the mechanism to enforce inbound restrictions based on the VPC.

214
MCQhard

Refer to the exhibit. An S3 bucket policy is set as shown. A developer tries to download an object from my-bucket using the AWS CLI from an IP address in the 203.0.113.0/24 range. What will happen?

A.The policy is invalid because of conflicting statements.
B.The download succeeds because the Allow statement matches the request.
C.The download succeeds because the Deny statement does not apply to GetObject.
D.The download fails with an AccessDenied error.
AnswerD

The AWS IAM policy evaluation logic follows a strict order of precedence. An explicit "Deny" statement, such as one using "s3:*" on the target resource, always overrides any "Allow" statements, even if an "Allow" statement specifically grants "s3:GetObject" permission. Since the request is explicitly denied by a matching "Deny" statement, the download attempt will result in an "AccessDenied" error, preventing the user from retrieving the object.

Why this answer

In an S3 bucket policy, explicit Deny statements override any Allow statements. Even though the Allow statement grants s3:GetObject to all principals, the Deny statement explicitly denies s3:GetObject when the request originates from the 203.0.113.0/24 IP range. Since the developer's IP falls within that range, the Deny takes precedence, resulting in an AccessDenied error.

Exam trap

The trap here is that candidates often assume that an Allow statement will always grant access, forgetting that an explicit Deny for the same action from a matching condition (like a source IP) takes precedence and causes the request to fail.

How to eliminate wrong answers

Option A is wrong because the policy is valid; S3 bucket policies can contain both Allow and Deny statements, and they are evaluated with Deny taking precedence over Allow. Option B is wrong because the Allow statement does match the request, but the explicit Deny statement for the same action from the specified IP range overrides it, causing the download to fail. Option C is wrong because the Deny statement explicitly applies to s3:GetObject, as it uses a wildcard '*' for actions, which includes GetObject.

215
MCQhard

A developer is deploying an application on EC2 instances behind an Application Load Balancer (ALB). The application must authenticate users using an identity provider (IdP) that supports OpenID Connect (OIDC). What is the MOST secure way to offload authentication to the ALB?

A.Configure the ALB with an OIDC identity provider and use the authenticate-oidc action.
B.Use AWS Lambda@Edge to authenticate users at the CloudFront edge.
C.Use IAM federation to trust the IdP and assign IAM roles to users.
D.Use Amazon Cognito User Pools and configure the ALB to use Cognito as the authentication provider.
AnswerA

The Application Load Balancer (ALB) natively supports OpenID Connect (OIDC) authentication through its `authenticate-oidc` action. This allows the ALB to delegate user authentication to an external OIDC identity provider (IdP). When a user attempts to access the application, the ALB redirects them to the IdP for login. Upon successful authentication, the IdP returns an ID token to the ALB, which validates it and then forwards the request to the backend EC2 instances, optionally injecting user claims as HTTP headers. This offloads authentication from the application code.

Why this answer

The ALB supports OIDC authentication natively through the `authenticate-oidc` action, which securely offloads user authentication to the IdP. This is the most secure and efficient approach because it keeps authentication at the edge of the load balancer. Option B is incorrect because Lambda@Edge is used with CloudFront, not directly with ALB.

Option C is incorrect because IAM federation is for granting AWS API access, not for web application authentication. Option D is incorrect because while Cognito User Pools can be used with ALB, the question specifies the organization already has an OIDC-compliant IdP; the ALB's native integration is more direct and secure than adding Cognito as an intermediary.

216
Multi-Selectmedium

A company wants to encrypt data at rest in an Amazon RDS for MySQL DB instance. Which of the following are true about RDS encryption? (Select THREE.)

Select 3 answers
A.Encryption at rest can be enabled on an existing unencrypted DB instance.
B.Encryption at rest can be enabled when you create the DB instance.
C.Snapshots of an encrypted instance are encrypted.
D.When encryption is enabled, automated backups are encrypted.
E.Read replicas of an encrypted instance can be unencrypted.
AnswersB, C, D

Encryption at rest is an instance-level configuration selected at the moment you create the DB instance. When you launch a new RDS database, you choose the 'Enable encryption' option and specify an AWS KMS key; from that point onward, all data on the underlying storage is AES-256 encrypted, and this setting cannot be changed after creation.

Why this answer

Option B is correct because RDS encryption at rest is configured at creation time: when you launch the DB instance you select an AWS KMS customer master key (CMK), and RDS uses it to encrypt the underlying storage, logs, and snapshots. Option C is correct because any DB snapshot taken from an encrypted instance is automatically encrypted with the same KMS key, so copies and restores of that snapshot remain encrypted. Option D is correct because automated backups of an encrypted DB instance are encrypted with the same KMS key as the instance, as are manual snapshots and read replicas.

Option A is not correct because you cannot enable encryption on an existing unencrypted instance in place; you must create an encrypted snapshot copy or restore into a new encrypted instance. Option E is not correct because a read replica of an encrypted instance must also be encrypted with the same KMS key; you cannot create an unencrypted read replica from an encrypted source.

Exam trap

The trap is believing you can toggle encryption on an existing RDS instance — the exam tests that encryption is set at creation and that snapshots/backups/replicas inherit it, while in-place enablement is impossible.

217
MCQeasy

A developer is encrypting an S3 bucket using server-side encryption with AWS KMS (SSE-KMS). What is a benefit of using SSE-KMS over SSE-S3?

A.Reduced latency for encrypted object retrieval
B.Lower cost than SSE-S3
C.Ability to control access to the encryption key separately
D.Automatic encryption of objects at rest
AnswerC

SSE-KMS provides enhanced security by allowing the encryption key, known as a Customer Master Key (CMK), to be managed independently within AWS KMS. Access to these CMKs is governed by dedicated key policies and IAM policies, enabling granular control over who can use the key for cryptographic operations, separate from S3 bucket permissions. This distinct management allows for a robust separation of duties, ensuring that access to data and access to its encryption key are controlled and auditable independently.

Why this answer

SSE-KMS allows you to use AWS KMS customer master keys (CMKs) to encrypt objects, giving you control over key access through KMS key policies and IAM. This separation of key management from data management is a key benefit over SSE-S3, where AWS manages the keys entirely. Thus, the ability to control access to the encryption key separately is the correct benefit.

Exam trap

DVA-C02 often tests the differences between S3 encryption options. Candidates may think SSE-KMS is always faster or cheaper, but it actually adds latency and cost due to KMS operations. The key benefit is control and auditability.

How to eliminate wrong answers

Option A is wrong because SSE-KMS can introduce additional latency due to KMS API calls, not reduce it. Option B is wrong because SSE-KMS may incur KMS request costs, making it potentially more expensive than SSE-S3. Option D is wrong because automatic encryption at rest is provided by both SSE-S3 and SSE-KMS; it is not a unique benefit of SSE-KMS.

218
MCQeasy

A company stores sensitive customer data in Amazon S3. The security policy requires that all data be encrypted at rest using server-side encryption with a customer-managed AWS KMS key. Which S3 server-side encryption option should the developer use?

A.SSE-S3
B.SSE-KMS
C.SSE-C
D.Client-side encryption
AnswerB

SSE-KMS utilizes AWS Key Management Service (KMS) to manage encryption keys, allowing customers to use either AWS-managed KMS keys or customer-managed keys (CMKs). This method provides a robust audit trail through AWS CloudTrail for key usage and enables granular access control policies on the keys themselves. It directly supports the requirement for customer-managed encryption keys by integrating with KMS, offering control over key lifecycle and permissions.

Why this answer

SSE-KMS is the correct option because it provides server-side encryption with a customer-managed AWS KMS key, allowing the company to control key rotation, access policies, and audit usage via AWS CloudTrail. This meets the security policy requirement for encryption at rest using a customer-managed key, which SSE-S3 (using AWS-managed keys) and SSE-C (using customer-provided keys) do not fulfill.

Exam trap

The trap here is that candidates often confuse SSE-KMS with SSE-S3, assuming both use AWS-managed keys, but SSE-KMS uniquely supports customer-managed keys and additional control features like key rotation and audit logging.

How to eliminate wrong answers

Option A (SSE-S3) is wrong because it uses AWS-managed keys, not customer-managed keys, so it does not meet the policy requirement for customer control over the encryption key. Option C (SSE-C) is wrong because it requires the customer to provide their own encryption keys in each request, and AWS does not manage or store the key, which contradicts the requirement for a customer-managed AWS KMS key. Option D (Client-side encryption) is wrong because it encrypts data before sending it to S3, not at rest on the server side, and does not use S3 server-side encryption at all.

219
MCQeasy

A developer is building a web application that must encrypt data in transit. Which AWS service should be used to manage SSL/TLS certificates?

A.AWS KMS
B.AWS Secrets Manager
C.AWS CloudHSM
D.AWS Certificate Manager (ACM)
AnswerD

AWS Certificate Manager (ACM) is the correct service for encrypting a web application because it fully automates the provisioning, management, and deployment of public and private SSL/TLS certificates. ACM handles the complex processes of certificate issuance, renewal, and binding to integrated AWS services like Elastic Load Balancers, CloudFront distributions, and API Gateways. This ensures secure, encrypted communication for web applications without manual intervention, simplifying certificate lifecycle management significantly.

Why this answer

AWS Certificate Manager (ACM) is the correct service because it is specifically designed to provision, manage, and deploy public and private SSL/TLS certificates for use with AWS services (e.g., Elastic Load Balancers, CloudFront, API Gateway). It handles the full lifecycle of certificates, including renewal, which directly addresses the requirement to encrypt data in transit using HTTPS.

Exam trap

The trap here is that candidates often confuse AWS KMS (used for encryption keys for data at rest) with SSL/TLS certificate management for data in transit, leading them to select KMS instead of ACM.

How to eliminate wrong answers

Option A is wrong because AWS KMS is a key management service for symmetric and asymmetric encryption keys used for data at rest, not for managing SSL/TLS certificates for data in transit. Option B is wrong because AWS Secrets Manager is designed to rotate and manage secrets such as database credentials and API keys, not SSL/TLS certificates. Option C is wrong because AWS CloudHSM provides dedicated hardware security modules for generating and storing encryption keys, but it does not manage SSL/TLS certificates or integrate directly with AWS services for automatic certificate deployment and renewal.

220
MCQeasy

A developer needs to securely store database credentials used by an application running on EC2. Which AWS service should be used?

A.AWS Secrets Manager
B.AWS Systems Manager Parameter Store
C.Amazon S3
D.AWS Certificate Manager (ACM)
AnswerA

AWS Secrets Manager is the optimal choice for securely storing and managing database credentials because it is purpose-built for secrets lifecycle management. It offers robust features such as automatic rotation of credentials, integration with various AWS databases like Amazon RDS, and fine-grained access control through AWS Identity and Access Management (IAM). This service ensures that credentials are automatically updated without requiring manual intervention, significantly enhancing security posture and reducing the risk of compromise.

Why this answer

AWS Secrets Manager is the correct choice because it is purpose-built for securely storing, rotating, and managing database credentials and other secrets throughout their lifecycle. It offers automatic rotation of credentials for Amazon RDS, Redshift, and DocumentDB with built-in integration, and it encrypts secrets at rest using AWS KMS. For an EC2 application, Secrets Manager can be accessed via the AWS SDK or CLI using IAM roles attached to the EC2 instance, ensuring credentials are never hardcoded or stored in plaintext.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store with Secrets Manager because both can store secrets, but Parameter Store does not support automatic rotation for database credentials, which is a key requirement for securely managing database credentials in production.

How to eliminate wrong answers

Option B is wrong because AWS Systems Manager Parameter Store is a hierarchical store for configuration data and secrets, but it lacks native automatic rotation for database credentials and does not provide the same level of integration with RDS or other database services as Secrets Manager. Option C is wrong because Amazon S3 is an object storage service designed for storing files and static data, not for securely managing sensitive credentials with built-in rotation and access control via IAM policies. Option D is wrong because AWS Certificate Manager (ACM) is specifically for managing SSL/TLS certificates, not for storing database credentials or other secrets.

221
MCQmedium

A company wants to enforce that all uploads to an Amazon S3 bucket must be encrypted using server-side encryption. The developer needs to write an IAM policy condition that denies any s3:PutObject request that does not include the server-side encryption header. Which IAM condition key should be used?

A.s3:x-amz-server-side-encryption
B.s3:x-amz-server-side-encryption-aws-kms-key-id
C.s3:x-amz-acl
D.s3:x-amz-storage-class
AnswerA

This condition key is used in an S3 bucket policy to evaluate the "x-amz-server-side-encryption" request header. By setting its value to "AES256" or "aws:kms" using a StringEquals operator, you can effectively mandate that all incoming PUT requests must include this header, thereby enforcing server-side encryption for all uploaded objects. This ensures data at rest is protected according to the specified encryption standard.

Why this answer

The `s3:x-amz-server-side-encryption` condition key matches the `x-amz-server-side-encryption` request header, which is used to specify server-side encryption (SSE-S3 or SSE-KMS) for S3 PutObject requests. By denying requests that do not include this header, the policy enforces that all uploads must be encrypted at rest using server-side encryption.

Exam trap

The trap here is that candidates confuse the condition key for requiring encryption (`s3:x-amz-server-side-encryption`) with the key for specifying a particular KMS key (`s3:x-amz-server-side-encryption-aws-kms-key-id`), leading them to pick option B when the question only asks about enforcing the presence of any server-side encryption header.

How to eliminate wrong answers

Option B is wrong because `s3:x-amz-server-side-encryption-aws-kms-key-id` is used to enforce a specific KMS key ID for SSE-KMS, not to require the presence of any server-side encryption header. Option C is wrong because `s3:x-amz-acl` controls access control list settings, not encryption. Option D is wrong because `s3:x-amz-storage-class` controls the storage class (e.g., STANDARD, GLACIER), not encryption.

222
MCQeasy

A developer is building a web application that must encrypt data in transit between the client and the server. Which AWS service should be used to offload SSL/TLS termination?

A.Application Load Balancer (ALB)
B.Amazon CloudFront
C.Network Load Balancer (NLB)
D.Amazon Route 53
AnswerA

An Application Load Balancer (ALB) operates at Layer 7 (application layer) and is specifically designed to handle HTTP/HTTPS traffic, making it ideal for web applications. It can offload the CPU-intensive SSL/TLS encryption and decryption process from backend instances, significantly improving their performance and simplifying certificate management. By configuring HTTPS listeners and associating an SSL/TLS certificate, typically from AWS Certificate Manager (ACM), the ALB terminates the secure connection from clients and forwards unencrypted or re-encrypted traffic to targets.

Why this answer

An Application Load Balancer (ALB) is ideal for web applications (HTTP/HTTPS) to offload SSL/TLS termination. It decrypts HTTPS traffic from clients at Layer 7 and forwards it to backend targets, reducing CPU load on application servers and centralizing certificate management via AWS Certificate Manager (ACM). While Network Load Balancer (NLB) also supports TLS termination at Layer 4, ALB is specifically designed for HTTP/HTTPS application-level routing and features.

Exam trap

Candidates often confuse the use cases of ALB and NLB for SSL/TLS termination. While both can terminate SSL/TLS, ALB operates at Layer 7 (HTTP/HTTPS) and is the standard choice for web applications requiring content-based routing, whereas NLB operates at Layer 4 (TCP/UDP/TLS) for ultra-high performance or static IP requirements.

How to eliminate wrong answers

Option B (Amazon CloudFront) is wrong because CloudFront is a content delivery network (CDN) that caches content at edge locations; while it can terminate SSL/TLS, its primary purpose is not to offload termination for a single web application but to accelerate delivery globally, and it does not function as a load balancer for backend targets. Option C (Network Load Balancer) is wrong because NLB operates at Layer 4 (TCP/UDP) and does not terminate SSL/TLS; it can pass through TLS traffic to targets but cannot decrypt it, so it cannot offload termination. Option D (Amazon Route 53) is wrong because Route 53 is a DNS service that resolves domain names to IP addresses; it has no capability to terminate SSL/TLS or handle HTTPS traffic.

223
Multi-Selecthard

A developer is deploying an application that uses Amazon SQS queues. The messages contain sensitive data that must be encrypted at rest. Which TWO actions should the developer take? (Choose TWO.)

Select 2 answers
A.Encrypt the messages client-side before sending to SQS.
B.Store the messages in an S3 bucket with default encryption instead of using SQS.
C.Configure the SQS queue to use a customer managed KMS key.
D.Enable server-side encryption (SSE) for the SQS queue using AWS KMS.
E.Use AWS CloudHSM to generate and store the encryption keys.
AnswersC, D

Configuring an SQS queue to use a Customer Managed Key (CMK) from AWS Key Management Service (KMS) is a correct approach to enable server-side encryption (SSE) for messages at rest. This option provides enhanced control over the encryption key, allowing developers to define specific key policies, manage key rotation schedules, and audit all key usage through AWS CloudTrail. SQS will then use this CMK to encrypt messages upon receipt and decrypt them automatically when consumers retrieve them, meeting the requirement for encryption at rest.

Why this answer

Configuring an SQS queue to use a customer managed KMS key gives you control over the key lifecycle, including rotation and access policies, while still leveraging AWS KMS for server-side encryption. Option D is also correct because enabling server-side encryption (SSE) for SQS using AWS KMS encrypts messages at rest automatically, without requiring client-side changes. Together, these two actions ensure that sensitive data in SQS messages is encrypted at rest using KMS, meeting the requirement.

Exam trap

The trap here is that candidates often think client-side encryption (Option A) is required for encryption at rest, but SQS SSE with KMS provides server-side encryption at rest without needing to modify the application code, making client-side encryption redundant for this specific requirement.

224
MCQhard

A developer is tasked with rotating database credentials stored in AWS Secrets Manager for an RDS MySQL instance. The rotation must occur automatically every 30 days. What is the BEST approach?

A.Store the credentials in AWS Systems Manager Parameter Store and use a scheduled Lambda to rotate them.
B.Use RDS automatic password rotation and have the application fetch the new password from RDS.
C.Use an IAM role for the RDS instance and rotate the role's credentials.
D.Configure automatic rotation in Secrets Manager using a rotation Lambda function.
AnswerD

AWS Secrets Manager is specifically designed for managing, retrieving, and rotating secrets, including database credentials. It offers a robust, integrated solution for automatic rotation by leveraging a rotation Lambda function. This function, either pre-built by AWS or custom, connects to the database, updates the user's password, and then updates the secret in Secrets Manager, ensuring applications always retrieve the current, rotated credentials securely.

Why this answer

Secrets Manager natively supports automatic rotation via a Lambda rotation function, and for RDS MySQL it provides a built-in rotation template that handles the two-step process of creating a new password and updating both the database and the secret. Configuring rotation with a 30-day schedule is a single setting in the console or CLI. This is the purpose-built, lowest-effort solution.

Exam trap

DVA-C02 often tests the misconception that Parameter Store or RDS itself handles credential rotation, when the correct answer is Secrets Manager's built-in rotation Lambda.

How to eliminate wrong answers

Option A is wrong because Parameter Store does not natively support rotation — you would have to build and maintain a custom Lambda, which is more work and less secure than the managed Secrets Manager rotation. Option B is wrong because RDS does not have an 'automatic password rotation' feature that the application can fetch from; RDS manages the master password only at creation or manual modification. Option C is wrong because IAM roles are for AWS API authentication, not for database user credentials — rotating an IAM role does not rotate the MySQL user's password.

225
MCQhard

An application uses Amazon Cognito user pools for authentication. A developer wants to restrict access to an API Gateway endpoint to only authenticated users from a specific user pool. What is the best approach?

A.Attach an IAM policy to the API Gateway resource that allows only the Cognito user pool ARN.
B.Use a Cognito User Pool authorizer in API Gateway.
C.Use an API Gateway resource policy that allows access only from the Cognito user pool.
D.Use a Lambda authorizer that validates the JWT token against the user pool.
AnswerB

The Cognito User Pool authorizer in API Gateway is the purpose-built, native solution for validating JWTs issued by Amazon Cognito User Pools. It automatically inspects the `Authorization` header for a valid JWT, verifies its signature against the user pool's public keys, checks its expiration, and confirms the issuer. Upon successful validation, API Gateway allows the request to proceed to the backend integration, often passing decoded token claims for application use.

Why this answer

A Cognito User Pool authorizer in API Gateway is the native, fully managed way to restrict access to an API endpoint to authenticated users from a specific user pool. It automatically validates the JWT token issued by the user pool and caches the result, requiring no custom code. This approach integrates directly with API Gateway's authorization flow, ensuring only tokens from the specified user pool are accepted.

Exam trap

The trap here is that candidates often overcomplicate the solution by choosing a Lambda authorizer (option D) because they think they need custom validation logic, forgetting that API Gateway has a built-in Cognito User Pool authorizer that handles JWT validation natively without any custom code.

How to eliminate wrong answers

Option A is wrong because IAM policies cannot reference a Cognito user pool ARN as a principal or resource for API Gateway; IAM policies control access based on IAM users/roles, not user pool identities. Option C is wrong because API Gateway resource policies control access by source IP, VPC, or AWS account, not by Cognito user pool tokens or user pool ARN. Option D is wrong because while a Lambda authorizer could validate a JWT against a user pool, it is unnecessary overhead and not the 'best approach' when a built-in Cognito User Pool authorizer exists that is simpler, faster, and requires no custom code.

← PreviousPage 3 of 5 · 314 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Security questions.