Courseiva

CCNA Troubleshooting and Optimization Questions

75 of 179 questions · Page 1/3 · Troubleshooting and Optimization · Answers revealed

1
MCQhard

A company is using Amazon DynamoDB with on-demand capacity. A developer notices that write requests are being throttled during peak hours. What is the MOST effective way to resolve this issue?

A.Switch to provisioned capacity mode with auto-scaling.
B.Increase the write capacity units.
C.Review the partition key design and consider adding a suffix to distribute writes.
D.Increase the read capacity units.
AnswerC

Reviewing the partition key design and considering adding a suffix to distribute writes is the correct approach because even with On-Demand capacity, Amazon DynamoDB enforces per-partition throughput limits. A 'hot partition' occurs when a single partition key value receives a disproportionately high volume of write requests, exceeding its individual throughput capacity and leading to throttling for operations targeting that specific key. By adding a random or time-based suffix to the partition key, writes are effectively spread across multiple logical partitions, thereby distributing the load more evenly and mitigating the impact of hot spots.

Why this answer

DynamoDB on-demand mode automatically scales to accommodate traffic, so throttling during peak hours usually indicates a hot partition caused by an unevenly distributed partition key. Adding a suffix (write sharding) distributes writes across more partitions, eliminating the hot partition and resolving throttling without changing capacity mode.

Exam trap

DVA-C02 often tests the misconception that on-demand mode eliminates all throttling, when in fact hot partitions can still throttle and require partition key redesign or write sharding.

How to eliminate wrong answers

Option A is wrong because switching to provisioned mode with auto-scaling does not fix a hot partition; auto-scaling reacts to overall table capacity, not per-partition skew. Option B is wrong because on-demand mode does not have write capacity units to increase, and even in provisioned mode, increasing WCU would not help if a single partition key is throttled. Option D is wrong because the issue is write throttling, not read throttling, so increasing read capacity units is irrelevant.

2
MCQhard

An application running on Amazon ECS Fargate is experiencing intermittent connection timeouts when calling an external API. The task has a public IP and a security group that allows outbound HTTPS. What is the most likely cause?

A.The ECS service is not configured to auto-assign public IP.
B.The task's security group does not allow inbound traffic.
C.The security group outbound rules are misconfigured.
D.The task is running in a private subnet without a NAT gateway.
AnswerD

ECS Fargate tasks deployed into a private subnet require a NAT Gateway to establish outbound connections to the internet. Private subnets are intentionally isolated from direct internet routing, meaning tasks within them cannot directly access external services or pull container images without an intermediary. A NAT Gateway, placed in a public subnet and configured with a route table entry for the private subnet, translates private IP addresses to its public IP, enabling secure and managed outbound internet access. This is the standard and necessary architecture for internet connectivity from private subnets.

Why this answer

ECS Fargate tasks running in a private subnet do not have direct internet access. Without a NAT gateway, outbound traffic to the external API is routed to the subnet’s route table, which lacks an internet gateway target, causing connection timeouts. The task’s public IP assignment is irrelevant in a private subnet, as the subnet itself has no route to the internet.

Exam trap

The trap here is that candidates assume a public IP on the task guarantees internet access, overlooking that the subnet’s route table determines whether traffic can reach the internet, and a private subnet without a NAT gateway blocks all outbound internet traffic regardless of the task’s public IP assignment.

How to eliminate wrong answers

Option A is wrong because the task already has a public IP assigned (as stated in the question), so the ECS service configuration for auto-assigning public IP is not the issue. Option B is wrong because inbound traffic rules are irrelevant for outbound HTTPS connections; the security group only needs to allow outbound traffic, which it does. Option C is wrong because the security group outbound rules are correctly configured to allow HTTPS (port 443), so misconfiguration is not the cause.

3
MCQeasy

A developer is troubleshooting an AWS Lambda function that times out when processing large files from Amazon S3. The function has a 15-minute timeout and 512 MB memory. What should the developer do to resolve this issue?

A.Use Amazon S3 batch operations to split the files before processing.
B.Add an S3 Event Notification to trigger the function asynchronously.
C.Reduce the Lambda timeout to 5 minutes to force faster processing.
D.Increase the Lambda function memory to 3008 MB.
AnswerD

Increasing the Lambda function memory to 3008 MB is a highly effective strategy for resolving timeout issues. In the AWS Lambda execution environment, the amount of allocated memory directly correlates with the proportional share of CPU power and network bandwidth provided to the function. By increasing memory, the function gains access to more computational resources, enabling it to process data faster, complete its tasks within the allowed timeout period, and improve overall performance for compute- or I/O-intensive workloads.

Why this answer

Increasing the Lambda function memory to 3008 MB is correct because Lambda allocates CPU proportionally to memory, and more CPU reduces processing time for CPU-bound tasks like file parsing. The 15-minute timeout is already the maximum, so the issue is insufficient compute resources, not timeout duration. With 512 MB, the function lacks the CPU throughput to process large files within the timeout, so boosting memory (and thus CPU) directly addresses the root cause.

Exam trap

The trap here is that candidates assume the 15-minute timeout is the problem and try to reduce it (Option C) or change invocation patterns (Option B), when the real issue is that Lambda's CPU allocation scales with memory, and insufficient memory leads to insufficient CPU for large file processing.

How to eliminate wrong answers

Option A is wrong because Amazon S3 Batch Operations are designed for bulk actions on existing objects (e.g., tagging, copying) and cannot split files before processing; splitting would require a separate preprocessing step, not a batch operation. Option B is wrong because adding an S3 Event Notification to trigger the function asynchronously does not change the function's execution environment or resource limits; it only changes invocation mode, and the function will still time out if it cannot process the file within the timeout. Option C is wrong because reducing the Lambda timeout to 5 minutes would make the problem worse—it would force the function to fail even faster, as it already times out at 15 minutes due to insufficient CPU.

4
MCQhard

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB). The application stores session data in an RDS MySQL database. Recently, users have reported that they are being logged out unexpectedly and their session data is lost. The developer investigates and finds that the RDS instance's CPU utilization spikes periodically, coinciding with the logout events. The application uses connection pooling via an RDS Proxy. The developer suspects that the session table is being dropped or truncated. After checking the application logs, the developer finds no evidence of truncation commands. The RDS instance has automated backups enabled, and the binary logs are retained for 24 hours. The developer wants to identify the root cause and prevent future occurrences. Which course of action should the developer take?

A.Enable Multi-AZ deployment for RDS to improve availability and prevent data loss during failover.
B.Increase the RDS instance size to handle the CPU spikes and prevent future issues.
C.Disable RDS Proxy and implement connection pooling in the application code to reduce database load.
D.Check the session table's storage engine; if it uses MEMORY, change it to InnoDB to persist data across restarts.
AnswerD

The MEMORY storage engine in MySQL stores all table data in RAM, providing extremely fast access but making the data volatile; any database restart, instance reboot, or crash will result in the complete loss of all data within these tables. Conversely, the InnoDB storage engine is ACID-compliant, writes data to disk, and includes robust crash recovery mechanisms, ensuring data persistence even after unexpected shutdowns. Changing the session table's engine to InnoDB directly addresses the problem of data loss upon restarts by making the data durable.

Why this answer

The MEMORY storage engine in MySQL stores table data in RAM and loses all rows when the MySQL server restarts (e.g., during a crash, failover, or maintenance). The periodic CPU spikes and session loss without any TRUNCATE/DROP in the logs strongly indicate the session table is using MEMORY and being wiped on restart. Converting the table to InnoDB persists data to disk and survives restarts, resolving the issue.

Exam trap

DVA-C02 often tests the MEMORY storage engine's volatility — candidates focus on CPU spikes and failover, missing that the real issue is a non-persistent storage engine losing data on restart.

How to eliminate wrong answers

Option A is wrong because Multi-AZ improves availability during failover but does not prevent data loss if the table uses a non-persistent storage engine — the data would still be lost on the standby. Option B is wrong because increasing instance size addresses CPU spikes but does not fix the root cause of session data loss; the MEMORY engine would still lose data on restart. Option C is wrong because RDS Proxy is not the cause of session loss; disabling it would not prevent the MEMORY table from being cleared on restart and would remove a useful connection-pooling feature.

5
Multi-Selecthard

A developer is optimizing an AWS Lambda function that processes streaming data from Amazon Kinesis. The function is CPU-bound. Which TWO actions should the developer take to improve performance?

Select 2 answers
A.Rewrite the function in a compiled language like Go.
B.Increase the function's reserved concurrency.
C.Increase the function's memory allocation.
D.Increase the Kinesis stream's shard count.
E.Enable GPU acceleration for the function.
AnswersA, C

Rewriting the function in a compiled language such as Go can significantly improve performance due to its direct compilation into machine code, eliminating the need for a runtime interpreter during execution. This results in faster execution speeds, lower CPU utilization per task, and often reduced cold start times compared to interpreted languages like Python or Node.js. Go's efficient concurrency model further aids in optimizing resource-intensive operations.

Why this answer

Option A is correct because rewriting a CPU-bound Lambda function in a compiled language such as Go reduces execution time: Go compiles to native machine code, avoids the JIT warm-up and higher memory overhead of interpreted runtimes like Python or Node.js, and typically delivers significantly faster CPU throughput for the same work. Option C is correct because in AWS Lambda, CPU power scales proportionally with the configured memory allocation; increasing memory from, say, 512 MB to 1769 MB grants roughly one full vCPU, which directly speeds up CPU-bound processing. Option B is wrong because reserved concurrency only caps or guarantees the number of simultaneous invocations; it does not make any single invocation faster and can even throttle throughput if set too low.

Option D is wrong because increasing Kinesis shard count raises stream throughput and parallelism across records, but it does not accelerate the CPU-bound work inside one function invocation. Option E is wrong because AWS Lambda does not support GPU acceleration; GPU-backed compute requires services like Amazon EC2, ECS, or SageMaker.

Exam trap

DVA-C02 often tests the misconception that reserved concurrency or shard count improves per-invocation performance, when in fact only memory allocation (and runtime choice) affects CPU available to a single Lambda invocation.

6
MCQeasy

A developer is using Amazon DynamoDB for a new application. The developer wants to reduce read latency. Which design pattern should the developer use?

A.Create a global secondary index (GSI) for the table.
B.Increase the provisioned read capacity units (RCUs) for the table.
C.Use DynamoDB Global Tables to replicate data to multiple regions.
D.Use DynamoDB Accelerator (DAX) as a cache for frequently read items.
AnswerD

DynamoDB Accelerator (DAX) is a fully managed, in-memory cache specifically designed to sit in front of DynamoDB tables, providing microsecond read latency for frequently accessed items. By caching read-heavy workloads, DAX significantly reduces the response time for repeated requests, offloading the DynamoDB table and improving application performance for read-intensive operations.

Why this answer

DynamoDB Accelerator (DAX) is an in-memory cache designed specifically for DynamoDB, providing microsecond read latency for frequently accessed items. By caching read-heavy workloads, DAX offloads requests from the DynamoDB table, reducing read latency without requiring application-level caching logic. This directly addresses the developer's goal of reducing read latency.

Exam trap

The trap here is that candidates often confuse increasing provisioned capacity (Option B) with reducing latency, when in fact it only increases throughput, while DAX (Option D) directly addresses latency by caching reads in memory.

How to eliminate wrong answers

Option A is wrong because a Global Secondary Index (GSI) provides an alternative query pattern or sort key, but does not inherently reduce read latency; it may even add latency due to asynchronous replication. Option B is wrong because increasing provisioned read capacity units (RCUs) improves throughput (handling more requests per second) but does not reduce per-request latency, as DynamoDB's read latency is already low and consistent regardless of RCU level. Option C is wrong because DynamoDB Global Tables replicate data across regions for disaster recovery and low-latency reads in remote regions, but for a single-region application, it adds complexity and cost without reducing local read latency.

7
MCQhard

An application uses an Amazon SQS queue to decouple microservices. The producer is sending messages, but the consumer is not processing them. The consumer is an Auto Scaling group of EC2 instances. The SQS queue's ApproximateNumberOfMessagesVisible metric is increasing. What is the MOST likely cause?

A.The SQS queue policy denies access to the consumer.
B.The consumer instances are not polling the SQS queue.
C.The visibility timeout is set too low.
D.The SQS queue has a dead-letter queue configured.
AnswerB

If consumer instances are not actively making ReceiveMessage API calls to the SQS queue, messages sent by producers will accumulate indefinitely. The ApproximateNumberOfMessagesVisible metric will continuously increase because no consumers are retrieving messages, thereby preventing them from being moved to the in-flight state or deleted. This scenario directly and most likely explains a sustained increasing trend of visible messages.

Why this answer

If the ApproximateNumberOfMessagesVisible metric keeps rising while the consumer Auto Scaling group is running, the most likely cause is that the consumer instances are not polling the queue at all. Without active long-polling ReceiveMessage calls, messages accumulate and are never processed, even though the queue and permissions may be fine. This is the most direct explanation for a growing visible-message count with no consumption.

Exam trap

DVA-C02 often tests the distinction between a growing message backlog caused by consumers not polling versus one caused by visibility timeout or DLQ settings, and candidates frequently blame queue configuration instead of the consumer's polling behavior.

How to eliminate wrong answers

Option A is wrong because a queue policy denying access would cause the consumer to receive AccessDenied errors, which would typically surface in logs and could still show messages accumulating, but the question asks for the MOST likely cause and a policy denial is less common than a polling misconfiguration. Option C is wrong because a low visibility timeout causes duplicate processing, not a growing backlog with no processing. Option D is wrong because a DLQ only receives messages after maxReceiveCount failures; it does not prevent normal consumption and would not by itself cause a growing visible count.

8
Multi-Selecthard

A developer is using AWS CodePipeline to deploy a web application. The pipeline has a source stage from GitHub and a deploy stage to Elastic Beanstalk. The deploy stage fails with the error 'The S3 bucket does not allow access to the artifact'. Which THREE actions could resolve this issue?

Select 3 answers
A.Specify a different artifact bucket in the pipeline configuration.
B.Add a bucket policy that grants the pipeline's service role access to the artifact bucket.
C.Ensure the pipeline's IAM role has s3:GetObject and s3:PutObject permissions on the artifact bucket.
D.If the artifact bucket is encrypted with AWS KMS, ensure the pipeline role has kms:Decrypt permission.
E.Enable versioning on the artifact bucket.
AnswersB, C, D

An S3 bucket policy is a resource-based policy attached directly to the S3 bucket, allowing you to grant permissions to AWS accounts, IAM users, or IAM roles, even across different AWS accounts. Adding a bucket policy that explicitly grants `s3:GetObject` and `s3:PutObject` (and potentially `s3:ListBucket`) permissions to the CodePipeline's service role ensures the pipeline has the necessary access to store and retrieve artifacts, complementing or overriding identity-based policies.

Why this answer

The deploy stage fails because the CodePipeline service role cannot access the artifact S3 bucket. To resolve this, you can: (1) Attach a bucket policy that grants the pipeline's service role access to the bucket (Option B). (2) Ensure the pipeline's IAM role has the necessary S3 permissions: s3:GetObject and s3:PutObject on the artifact bucket (Option C). (3) If the artifact bucket uses AWS KMS encryption, the pipeline role also needs kms:Decrypt permission to read the encrypted artifacts (Option D). Option A is not a direct fix — specifying a different bucket may avoid the issue but does not address the access problem with the current bucket.

Option E is irrelevant because bucket versioning does not affect access permissions.

9
MCQmedium

A developer is deploying a serverless application using AWS CloudFormation. The stack creation fails with the error 'CREATE_FAILED: The following resource(s) failed to create: [MyLambdaFunction]'. The developer checks the CloudFormation events and sees 'Resource creation cancelled'. What is the most likely cause?

A.The Lambda function code is too large and exceeds the deployment limit.
B.The Lambda function creation timed out due to a network issue.
C.Another resource in the stack failed, triggering a rollback and cancelling the Lambda creation.
D.The Lambda function's execution role is missing permissions.
AnswerC

When deploying resources using AWS CloudFormation, the deployment process is atomic. If any single resource within a CloudFormation stack fails to create, update, or delete, CloudFormation initiates an automatic rollback of the entire stack to its last stable state. In this scenario, if the Lambda function was pending creation or in the process of being created when another resource in the same stack encountered a failure, its creation would be explicitly cancelled as part of this rollback mechanism, resulting in the 'Resource creation cancelled' status.

Why this answer

When CloudFormation creates a stack, resources are provisioned in dependency order. If any resource fails, CloudFormation initiates a rollback and cancels in-progress creations of other resources — producing the 'Resource creation cancelled' message for MyLambdaFunction. The Lambda itself did not fail; it was cancelled because a sibling resource failed first.

Exam trap

DVA-C02 often tests whether candidates chase the visible error ('Resource creation cancelled') instead of identifying the root-cause resource that failed first and triggered the rollback.

How to eliminate wrong answers

Option A is wrong because an oversized Lambda deployment package would produce a specific error like 'Code storage limit exceeded' or 'RequestEntityTooLarge', not 'Resource creation cancelled'. Option B is wrong because a network timeout would surface as a timeout error on the Lambda resource itself, not a cancellation triggered by another resource. Option D is wrong because a missing IAM permission on the execution role would cause the Lambda to fail at invocation time or produce an explicit 'AccessDenied' during creation, not a cancellation message.

10
MCQmedium

A web application running on EC2 instances behind an Application Load Balancer (ALB) is experiencing intermittent 503 errors. The ALB target group health checks are succeeding. Which step should the developer take FIRST to diagnose the issue?

A.Increase the number of EC2 instances in the target group.
B.Examine the ALB access logs for 503 responses.
C.Check the Route 53 record for the ALB.
D.Verify that the EC2 instances are in a running state.
AnswerB

Examining ALB access logs is the most effective diagnostic step because these logs capture detailed information about every request processed by the load balancer, including the HTTP status code returned to the client and the target status code from the EC2 instance. Filtering for 503 responses ("HTTP 503" or "target_status_code:503") allows identification of specific request patterns, source IPs, or target groups that are experiencing issues. This data helps pinpoint whether the 503s are due to application errors, target connection issues, or other load balancer-related problems.

Why this answer

The correct first step is to examine the ALB access logs for 503 responses. Since health checks are succeeding, the EC2 instances are considered healthy by the target group, but the ALB itself may be returning 503 errors due to issues like request rate limits, connection limits, or backend response timeouts. Access logs provide detailed HTTP response codes and timestamps, allowing you to identify the pattern and cause of the 503 errors without making assumptions about instance count or state.

Exam trap

The trap here is that candidates assume 503 errors always mean unhealthy instances, so they jump to checking instance state or scaling, ignoring that health checks are passing and that ALB-level issues (like connection limits or timeouts) are the actual cause.

How to eliminate wrong answers

Option A is wrong because increasing the number of EC2 instances does not address the root cause of 503 errors when health checks are passing; it may mask the issue but does not diagnose it. Option C is wrong because Route 53 records only affect DNS resolution, not the ALB's ability to forward requests to healthy targets; a misconfigured Route 53 record would cause different errors (e.g., 503 or connection failures) but checking it first is premature when the ALB itself is reachable. Option D is wrong because the health checks are succeeding, which already confirms the EC2 instances are in a running state and responding to health check pings; verifying instance state again is redundant and does not explain the intermittent 503 errors.

11
MCQeasy

A developer is deploying a serverless application using AWS SAM. The deployment fails with the error 'Resource creation cancelled'. What is the most likely cause?

A.The SAM template is malformed.
B.A resource in the stack failed to create.
C.The Lambda function code has a timeout.
D.The IAM role does not have sufficient permissions.
AnswerB

'Resource creation cancelled' is CloudFormation's standard rollback behavior: when one resource in the stack fails to create (for example, an S3 bucket name collision or an invalid property value), CloudFormation cancels the creation of any remaining resources that haven't started yet and begins rolling back what did get created.

Why this answer

The 'Resource creation cancelled' error in AWS SAM indicates that the CloudFormation stack creation was cancelled because one or more resources failed to create, triggering a rollback. Option A is incorrect because a malformed SAM template would produce a validation error, not 'Resource creation cancelled'. Option C is incorrect because a Lambda function timeout is a runtime issue, not a deployment error.

Option D is incorrect because insufficient IAM permissions would result in an access denied error, not this specific cancellation message.

12
Multi-Selecthard

A Lambda function reading from Kinesis is falling behind. Which two metrics/settings should be reviewed first?

Select 2 answers
A.IteratorAge for the event source mapping
B.S3 bucket public access settings
C.Route 53 hosted zone count
D.Batch size, parallelization factor, and shard count
AnswersA, D

IteratorAge is a critical Amazon Kinesis Streams metric, reported by the Event Source Mapping, that measures the age of the last record successfully processed by the Lambda function. A consistently high or increasing IteratorAge directly indicates that the Lambda function is falling behind in processing records from the Kinesis stream. This metric provides a real-time, direct measurement of the processing lag, making it the primary indicator for diagnosing such issues.

Why this answer

The IteratorAge metric measures how far behind the Lambda function is in processing records from the Kinesis stream. A high IteratorAge indicates the function is falling behind, making it the primary metric to review. The batch size, parallelization factor, and shard count directly control the concurrency and throughput of the event source mapping, so adjusting these settings can help catch up.

Exam trap

The trap here is that candidates may overlook the direct performance-tuning metrics (IteratorAge, batch size, parallelization factor) and instead focus on unrelated AWS services like S3 or Route 53, which are red herrings in this troubleshooting context.

13
MCQeasy

A developer is deploying a CloudFormation stack and sees the event above. What should the developer do to fix the error?

A.Update the Lambda function code to use a different programming language.
B.Increase the Lambda function timeout in the template.
C.Change the runtime to a supported version like nodejs18.x.
D.Add permissions to the Lambda function's execution role.
AnswerC

AWS Lambda regularly deprecates older runtime versions to ensure security, performance, and maintainability. When a CloudFormation stack specifies a runtime that is no longer supported (e.g., `nodejs12.x` or `python3.7`), the deployment will fail with an explicit error indicating the runtime is invalid. Updating the `Runtime` property in the CloudFormation template to a currently supported version, such as `nodejs18.x` or `python3.9`, directly resolves this specific deployment failure.

Why this answer

The error indicates that the runtime (Node.js 12.x) used in the Lambda function is deprecated and no longer supported by AWS. To fix this, the developer must update the CloudFormation template to specify a supported runtime version, such as nodejs18.x, and redeploy the stack. Option C correctly identifies this solution.

Option A is incorrect because the programming language itself is not the issue; the runtime version needs updating. Option B is incorrect because increasing the timeout does not address the unsupported runtime. Option D is incorrect because adding permissions does not resolve the runtime deprecation error.

14
MCQeasy

An application running on Amazon ECS with Fargate is unable to pull an image from Amazon ECR. The task definition uses the 'default' task execution role. What is the most likely cause?

A.The task role does not have permissions to access ECR.
B.The ECS cluster does not have permissions to access ECR.
C.The ECS service role does not have permissions to access ECR.
D.The task execution role does not have permissions to pull from ECR.
AnswerD

The Amazon ECS task execution role grants permissions to the ECS agent or the Fargate infrastructure to perform essential actions on your behalf, *before* your application code even starts. This includes crucial operations such as pulling container images from Amazon ECR, pushing container logs to Amazon CloudWatch Logs, and retrieving sensitive data from AWS Secrets Manager or Parameter Store for image pull authentication. For successful image retrieval, this role specifically requires permissions like `ecr:GetDownloadUrlForLayer`, `ecr:BatchGetImage`, and `ecr:BatchCheckLayerAvailability` to authenticate and download image layers, without which the task launch will fail.

Why this answer

When using Amazon ECS with Fargate, the task execution role (not the task role) is responsible for pulling container images from Amazon ECR. The 'default' task execution role is created automatically but lacks the necessary permissions (e.g., ecr:GetDownloadUrlForLayer, ecr:BatchGetImage, and ecr:BatchCheckLayerAvailability) unless explicitly attached via an IAM policy. Since the question states the task definition uses the 'default' task execution role, the most likely cause is that this role does not have the required ECR permissions.

Exam trap

The trap here is that candidates often confuse the task execution role with the task role, assuming the task role handles all permissions including image pulling, when in fact the task execution role is a separate IAM role specifically required for ECR image pulls and CloudWatch Logs.

How to eliminate wrong answers

Option A is wrong because the task role is used by the application code running inside the container to interact with AWS services (e.g., DynamoDB, S3), not for pulling images from ECR; image pulling is handled by the ECS agent using the task execution role. Option B is wrong because an ECS cluster itself does not have an IAM role or permissions; permissions are assigned to the task execution role or the ECS service role, not to the cluster resource. Option C is wrong because the ECS service role (formerly ecsServiceRole) is used for actions like registering/deregistering targets with a load balancer, not for pulling container images from ECR; image pulling is exclusively the responsibility of the task execution role.

15
MCQmedium

A developer is troubleshooting an AWS Lambda function that is triggered by an Amazon SQS queue. The function processes messages but occasionally fails. The failed messages are not being sent to the dead-letter queue (DLQ). What is the most likely reason?

A.The Lambda function's execution role does not have permission to send messages to the DLQ.
B.The SQS queue's redrive policy is not configured.
C.The Lambda function's reserved concurrency is set to 0.
D.The Lambda function does not have a dead-letter queue configured.
AnswerB

When an AWS Lambda function processes messages from an SQS queue, and an invocation fails (e.g., due to an error in the function code or a timeout), SQS will return the message to the queue after its visibility timeout expires. If the message processing continues to fail and the SQS queue does not have a redrive policy configured, the message will eventually be discarded by SQS after its maximum receive count is exceeded, rather than being moved to a Dead-Letter Queue (DLQ). Therefore, a missing redrive policy directly prevents failed messages from being captured in a DLQ associated with the source queue.

Why this answer

For Lambda functions triggered by SQS, the dead-letter queue is configured on the SQS queue via its redrive policy, not on the Lambda function. If the redrive policy is missing or misconfigured, failed messages will not be moved to a DLQ even if the Lambda function has its own DLQ configured. The most likely reason is that the SQS queue's redrive policy is not configured.

Exam trap

The trap is assuming the Lambda function's DLQ configuration applies to SQS triggers — candidates often miss that SQS-triggered invocations use the queue's redrive policy, not Lambda's DLQ.

How to eliminate wrong answers

Option A is wrong because the Lambda execution role's permissions are not the issue — the redrive policy on the SQS queue governs DLQ behavior, and the queue's own permissions matter, not the Lambda role's. Option C is wrong because reserved concurrency set to 0 would prevent the function from processing any messages at all, not cause occasional failures without DLQ delivery. Option D is wrong because Lambda's own DLQ configuration applies to asynchronous invocations, not to SQS-triggered (poll-based) invocations; for SQS, the DLQ is configured on the queue.

16
MCQmedium

A developer monitors an AWS Lambda function that processes messages from an Amazon SQS queue. CloudWatch logs show that the function's execution time has increased significantly over the past week. The function's code has not been changed recently. The function makes calls to an Amazon DynamoDB table. CloudWatch metrics show a high rate of DynamoDBProvisionedThroughputExceededException errors. The DynamoDB table has 5 read and 5 write capacity units (RCU/WCU). What is the most effective action to reduce the function's execution time?

A.Increase the Lambda function's memory allocation.
B.Increase the Lambda function's reserved concurrency.
C.Increase the DynamoDB table's read and write capacity units.
D.Increase the Lambda function's timeout.
AnswerC

Increasing the table's provisioned RCU and WCU directly removes the throttling that causes DynamoDBProvisionedThroughputExceededException, so the Lambda function's DynamoDB calls stop retrying with exponential backoff. Those retry delays, not the function's code, explain the inflated execution time, and raising capacity addresses the 5 RCU/5 WCU constraint named in the stem.

Why this answer

The high rate of DynamoDBProvisionedThroughputExceededException errors indicates that the Lambda function is being throttled by DynamoDB due to insufficient read and write capacity units. This throttling causes the function to retry operations, significantly increasing execution time. Increasing the RCU/WCU from 5 to a higher value directly addresses the bottleneck, allowing operations to complete without retries and reducing overall execution time.

Exam trap

The trap here is that candidates often confuse performance issues caused by Lambda resource limits (memory, concurrency, timeout) with downstream service throttling, leading them to adjust Lambda settings instead of addressing the root cause in DynamoDB capacity.

How to eliminate wrong answers

Option A is wrong because increasing memory allocation improves CPU performance and execution speed for compute-bound tasks, but the issue here is a DynamoDB throughput limitation, not a lack of compute resources. Option B is wrong because reserved concurrency controls how many concurrent Lambda invocations are allowed, which does not affect the per-invocation execution time or resolve DynamoDB throttling errors. Option D is wrong because increasing the timeout only allows the function to run longer before being terminated, but it does not reduce the actual time taken to process each message; the function will still be delayed by DynamoDB retries.

17
MCQeasy

A developer reports that an AWS Lambda function is timing out after 3 seconds. The function reads from an Amazon SQS queue. What is the most likely cause?

A.The Lambda function memory is set too low, causing slow execution.
B.The Lambda function timeout is set to 3 seconds, which is too low.
C.The Lambda execution role lacks permissions to poll SQS.
D.The SQS queue is empty, causing the function to wait indefinitely.
AnswerB

AWS Lambda functions have a configurable timeout setting, with a default value of 3 seconds. If the function's execution logic, including any external API calls or complex processing, exceeds this configured duration, Lambda will forcibly terminate the invocation and report a timeout error. This is a common and direct cause for consistent timeouts occurring at a specific, short duration.

Why this answer

The Lambda function is timing out after exactly 3 seconds because its configured timeout is set to 3 seconds, which is too low for the workload. Lambda has a maximum execution timeout of 15 minutes (900 seconds), but the default timeout is 3 seconds. Since the function reads from an SQS queue, it likely needs more time to process messages, and increasing the timeout value will resolve the issue.

Exam trap

The trap here is that candidates often confuse timeout with memory or permissions issues, but the exact 3-second timeout is a direct indicator of the default Lambda timeout being too low, not a resource or authorization problem.

How to eliminate wrong answers

Option A is wrong because low memory can cause slower execution, but it would not cause a hard timeout at exactly 3 seconds; memory affects performance, not the timeout limit. Option C is wrong because if the execution role lacked permissions to poll SQS, the function would fail with an access denied error (e.g., 403 or 500), not a timeout. Option D is wrong because an empty SQS queue does not cause a Lambda function to wait indefinitely; Lambda polls the queue and returns immediately if no messages are available, and the function would complete quickly without timing out.

18
MCQeasy

A developer is using Amazon DynamoDB as the database for a web application. The application experiences occasional spikes in traffic, and some write requests fail with a ProvisionedThroughputExceededException. What is the MOST cost-effective way to handle these spikes without manual intervention?

A.Switch to on-demand mode for the table.
B.Enable DynamoDB auto scaling for the table.
C.Increase the provisioned write capacity to the peak expected value.
D.Use DynamoDB Accelerator (DAX) to cache writes.
AnswerB

DynamoDB auto scaling continuously monitors consumed capacity through CloudWatch alarms and automatically raises or lowers the table's provisioned read and write capacity units within configured min/max bounds and a target utilization percentage, absorbing traffic spikes without manual intervention while keeping baseline costs lower than a flat over-provisioned or fully on-demand configuration.

Why this answer

DynamoDB auto scaling automatically adjusts the provisioned read and write capacity based on actual traffic patterns, handling spikes without manual intervention and only paying for the capacity needed at peak times. Option A (on-demand mode) avoids capacity management but can be more expensive for predictable workloads or sustained traffic. Option C (increasing to peak) leads to over-provisioning and higher cost during low traffic.

Option D (DAX) is a caching layer for reads, not writes, and does not address write throughput limitations.

19
MCQhard

A web application runs on Amazon EC2 instances behind an Application Load Balancer (ALB). During peak hours, users report receiving HTTP 503 (Service Unavailable) errors. The developer checks Amazon CloudWatch metrics and finds that the ALB's request count is high but below the limit, and the target group's healthy host count drops to zero intermittently. The Auto Scaling group for the instances is configured with a minimum of 2, maximum of 10, and a simple scaling policy to add 2 instances when CPU utilization exceeds 70% for 5 consecutive minutes. What is the most likely cause of the 503 errors?

A.The Auto Scaling group's cooldown period prevents new instances from being added quickly enough during rapid traffic spikes
B.The ALB's idle timeout is set too low, causing dropped connections
C.The Auto Scaling group's maximum capacity of 10 is insufficient
D.The health check grace period is preventing instances from being marked healthy
AnswerA

During a rapid traffic spike, an Auto Scaling group's cooldown period, typically 300 seconds by default, prevents additional scaling activities from initiating immediately after a previous one. This delay means that even if the scaling policy is triggered multiple times, new instances cannot launch quickly enough to meet the escalating demand. Consequently, existing instances become overloaded and unhealthy, leading to 503 Service Unavailable errors as the application cannot process requests.

Why this answer

The 503 errors occur because the simple scaling policy has a cooldown period (default 300 seconds) that prevents the Auto Scaling group from launching new instances during rapid traffic spikes. When CPU exceeds 70% for 5 minutes, the policy adds 2 instances, but the cooldown blocks further scaling actions until it expires, even if the newly launched instances are still initializing and the healthy host count drops to zero. This mismatch between traffic demand and scaling responsiveness causes the ALB to have no healthy targets, resulting in 503 errors.

Exam trap

The trap here is that candidates often assume 503 errors are always due to capacity limits (Option C) or misconfigured health checks (Option D), but the real issue is the cooldown period's impact on scaling responsiveness during rapid traffic spikes.

How to eliminate wrong answers

Option B is wrong because the ALB's idle timeout (default 60 seconds) controls how long the ALB keeps a connection open without data transfer; it does not cause 503 errors or affect target health status. Option C is wrong because the maximum capacity of 10 is not the issue—the healthy host count drops to zero intermittently, indicating a scaling responsiveness problem, not a capacity ceiling. Option D is wrong because the health check grace period (default 300 seconds) delays the start of health checks for newly launched instances, but it does not cause healthy hosts to drop to zero; it only postpones marking them healthy, which would not explain intermittent drops in an already-running group.

20
MCQhard

An application running on EC2 instances behind an Application Load Balancer (ALB) occasionally returns HTTP 503 errors. The instances are in an Auto Scaling group. Which action should be taken to resolve this issue?

A.Enable cross-zone load balancing on the ALB.
B.Review the ALB access logs to identify the target response codes.
C.Increase the ALB idle timeout setting.
D.Increase the size of the EC2 instances.
AnswerB

ALB access logs record target response codes and timing, revealing whether 503s originate from unhealthy targets, connection limits or application errors. Reviewing them identifies the actual failure source before remediation, satisfying the need to diagnose rather than guess at scaling or health-check changes.

Why this answer

HTTP 503 errors from an ALB indicate that the targets (EC2 instances) are not responding successfully. Reviewing ALB access logs reveals the specific target response codes (e.g., 503 from the target itself or connection timeouts), which helps pinpoint whether the issue is due to overloaded instances, application errors, or health check failures. This diagnostic step is essential before making any configuration changes.

Exam trap

The trap here is that candidates often jump to scaling or instance size changes (Option D) without first using access logs to diagnose whether the 503s originate from the ALB or the targets, leading to ineffective fixes.

How to eliminate wrong answers

Option A is wrong because cross-zone load balancing is enabled by default on ALBs and affects traffic distribution across Availability Zones, not the root cause of 503 errors from unresponsive targets. Option C is wrong because the ALB idle timeout setting controls how long the ALB keeps a connection open without data transfer; increasing it does not resolve 503 errors caused by target failures or overload. Option D is wrong because simply increasing EC2 instance size may mask the problem but does not address the underlying cause (e.g., application bugs, scaling policies, or health check misconfigurations) and could lead to unnecessary cost.

21
MCQmedium

Refer to the exhibit. A developer invoked a Lambda function and received this response. What does the FunctionError field indicate?

A.The function executed successfully.
B.The function threw an unhandled exception.
C.The function was throttled.
D.The function timed out.
AnswerB

When FunctionError is set to 'Unhandled', it means the function code threw an exception or exited abnormally without a surrounding try/catch (or equivalent) that intercepted it, so the Lambda runtime itself caught the failure and reported it back in the invoke response. The response payload also typically contains an errorMessage and stack trace describing the exception.

Why this answer

FunctionError: Unhandled indicates that the function threw an exception that was not caught by the code. Option A is wrong because StatusCode 200 means invocation succeeded. Option C is wrong because throttling would return 429.

Option D is wrong because configuration errors would return 400.

22
MCQmedium

A developer notices that an AWS Lambda function configured with a VPC is timing out when trying to access an Amazon S3 bucket. The function has the necessary IAM permissions. What is the most likely cause?

A.Lambda functions cannot be configured inside a VPC.
B.The Lambda function's execution role lacks S3 permissions.
C.The Lambda function does not have a route to the internet or a VPC endpoint for S3.
D.The security group attached to the Lambda function does not allow outbound traffic to S3.
AnswerC

This is correct. When a Lambda function is configured inside a VPC, it loses internet access by default. To access S3, the function needs either a VPC endpoint for S3 or a route to the internet via a NAT Gateway/Instance. Without this, the function times out.

Why this answer

When a Lambda function is attached to a VPC, it loses the default internet access it normally has and can only reach resources within that VPC's subnets. To reach S3, the function must either route through a NAT gateway/instance to the public internet or use an S3 Gateway VPC Endpoint, which provides private connectivity without traversing the internet.

Exam trap

DVA-C02 often tests the misconception that security groups block outbound traffic by default — they don't (they're stateful and allow all egress unless restricted), so the real culprit in VPC-attached Lambda timeouts is almost always missing NAT or VPC endpoint routing.

How to eliminate wrong answers

Option A is wrong because Lambda functions absolutely can be configured inside a VPC — this is a supported and common configuration. Option B is wrong because the question explicitly states the function already has the necessary IAM permissions, so the execution role is not the issue. Option D is wrong because security groups are stateful and by default allow all outbound traffic; the more common cause of S3 timeouts from VPC-attached Lambda is the missing route/endpoint, not the security group egress rules.

23
MCQmedium

A developer deploys an application on EC2 instances behind an Application Load Balancer (ALB). The application uses sticky sessions (session affinity) based on a cookie. Users report that they are intermittently logged out during their session. What is the MOST likely cause?

A.The deregistration delay value is too low, causing connections to be dropped during scaling events.
B.The ALB health check interval is too short, causing healthy instances to be marked unhealthy frequently.
C.Cross-zone load balancing is disabled, causing uneven traffic distribution.
D.The stickiness cookie expiration duration is set too low, causing the cookie to expire before the user's session ends.
AnswerD

The ALB's stickiness configuration includes a cookie duration setting (1 second to 7 days) that determines how long the AWSALB cookie remains valid; if this duration is shorter than a typical user session, the cookie expires mid-session, the ALB then routes the next request to a different, possibly unauthenticated, backend instance, and the application-level session appears to log the user out.

Why this answer

If the stickiness cookie expiration duration is set too low, the cookie will expire before the user's session ends, causing the load balancer to route the user to a different instance and losing session state. Option A is wrong because deregistration delay affects how long an instance remains in service during scaling events, but does not directly cause intermittent logouts during a session. Option B is wrong because a short health check interval might cause healthy instances to be marked unhealthy, but this would result in dropped connections, not specifically intermittent logouts due to session stickiness.

Option C is wrong because cross-zone load balancing affects traffic distribution across zones, not session stickiness.

24
MCQhard

A company runs a production web application on EC2 instances behind an Application Load Balancer. Users report intermittent 502 errors. The developers find that the ALB access logs show 'target_response_code' of 502 for some requests. What is the MOST likely cause?

A.The EC2 instances are unable to resolve DNS for the ALB.
B.The security group for the EC2 instances is blocking traffic from the ALB.
C.The EC2 instances are closing idle connections prematurely due to a short keep-alive timeout.
D.The ALB health checks are failing and the target group has unhealthy instances.
AnswerC

When an Application Load Balancer (ALB) forwards a request to a target EC2 instance, it maintains a persistent connection using HTTP keep-alive. If the EC2 instance's web server (e.g., Apache, Nginx, or application server) has a `keep-alive_timeout` configured to be shorter than the ALB's idle timeout (default 60 seconds) or the time it takes for the ALB to send the full request or receive the full response, the instance might prematurely close the TCP connection. This abrupt closure, while the ALB is still expecting a response or attempting to send data, results in the ALB receiving an unexpected connection termination, which it translates into an HTTP 502 Bad Gateway error for the client.

Why this answer

The 502 Bad Gateway error from an Application Load Balancer indicates that the target (EC2 instance) closed the connection before the ALB could finish writing the request or reading the response. This commonly occurs when the keep-alive timeout on the EC2 instance is set too low, causing idle connections to be closed prematurely. Option A is incorrect because DNS resolution issues would not cause a 502; they would cause a 503 or connection failure.

Option B is incorrect because a security group blocking traffic would result in health check failures and a 503, not a 502. Option D is incorrect because unhealthy instances would cause a 503, not a 502.

25
MCQhard

A developer is using AWS CodePipeline to automate a multi-stage pipeline. The pipeline includes a manual approval step before deploying to production. The developer wants to receive an email notification when the pipeline reaches the approval step. Which service should the developer use?

A.Configure CodePipeline to send an email using the 'Email' action
B.Use Amazon CloudWatch Logs to monitor the pipeline logs and trigger an alarm
C.Use Amazon Simple Email Service (SES) to send an email from the pipeline
D.Use Amazon CloudWatch Events to detect the pipeline state change and trigger an SNS notification
AnswerD

Amazon CloudWatch Events (now EventBridge) provides a robust mechanism for monitoring and reacting to state changes across AWS services, including CodePipeline. CodePipeline emits events for various execution states, such as pipeline execution, stage execution, and action execution. A CloudWatch Event rule can be configured to specifically detect a CodePipeline stage entering a `WAITING_FOR_APPROVAL` state, and then trigger an Amazon SNS topic to send immediate notifications to subscribed users or systems. This approach leverages the native eventing capabilities of AWS services for efficient, real-time communication.

Why this answer

CloudWatch Events (now part of Amazon EventBridge) can detect pipeline state changes such as a manual approval step entering a 'waiting' state. You can create a rule that matches this event and targets an Amazon SNS topic to send an email notification. Option A is incorrect because CodePipeline does not have an 'Email' action built-in.

Option B is incorrect because CloudWatch Logs is used for monitoring log data, not for triggering notifications directly. Option C is incorrect because while Amazon SES can send emails, it is not directly integrated with CodePipeline; the recommended approach is to use CloudWatch Events with SNS for notifications.

26
MCQeasy

A developer is deploying an AWS Elastic Beanstalk application and notices that the environment's health is degraded because the application is returning HTTP 5xx errors. The developer wants to quickly identify the root cause without redeploying. Which action should the developer take?

A.Increase the environment's instance type to handle more traffic.
B.Retrieve the full logs from the environment using the EB CLI and inspect the application log files.
C.Disable rolling deployments and redeploy the application with a new version.
D.Rebuild the environment to reset the instances and clear any transient issues.
AnswerB

Elastic Beanstalk provides the eb logs command, which bundles and retrieves logs from the environment's instances, including the application server logs, web server logs, and EB platform logs. Inspecting these logs reveals stack traces, errors, and configuration issues causing the 5xx responses. This is the fastest way to diagnose without redeploying.

Why this answer

The eb logs command retrieves logs from the environment's instances, including application and web server logs, which contain the error details needed to diagnose 5xx responses. This is the standard troubleshooting step for Elastic Beanstalk environments. The other options either mask the problem, add cost, or do not provide diagnostic data.

Exam trap

The trap here is assuming that redeploying or rebuilding the environment is a troubleshooting step, when in fact it can destroy the evidence needed to find the root cause.

27
MCQhard

A developer optimized an Amazon S3 bucket for high request rates. The bucket receives over 5,000 PUT requests per second. Recently, some requests are failing with a 503 Slow Down error. What is the most likely cause and how should the developer fix it?

A.Use multipart upload for all objects to improve throughput.
B.The request rate exceeds the account-level PUT quota; request a quota increase.
C.The bucket policy is too permissive; restrict access to prevent abuse.
D.Add a random prefix to the object keys to distribute across partitions.
AnswerD

Amazon S3 distributes data across multiple partitions internally, with object keys serving as the basis for this distribution. By adding a random prefix to object keys, requests are spread across a wider range of S3 partitions, preventing a single prefix from becoming a 'hot spot.' This strategy effectively increases the aggregate request rate capacity for the bucket, mitigating 503 'Slow Down' errors by distributing the load.

Why this answer

S3 returns 503 when request rates exceed partition limits. Prefix randomization spreads requests across partitions. Option A is wrong because 503 is not due to permissions.

Option B is wrong because 503 is not a quota limit exceeded error (that would be 400). Option C is wrong because multipart upload is for large objects, not rate limits.

28
MCQhard

A developer is using Amazon CloudFront to distribute content from an S3 bucket. The bucket is configured as an origin with Origin Access Control (OAC). Recently, some users have reported that they receive 403 Forbidden errors when accessing certain objects. The developer checks the CloudFront distribution and confirms that the OAC is set up correctly. The S3 bucket policy allows the CloudFront service principal to get objects. The developer also notes that the objects in question have been updated recently. What is the MOST likely cause of the 403 errors?

A.The objects are encrypted with SSE-C (server-side encryption with customer-provided keys).
B.The OAC configuration is not correctly associated with the CloudFront distribution.
C.The S3 bucket policy denies access to the CloudFront service principal.
D.The CloudFront distribution is configured to use the S3 website endpoint instead of the REST endpoint.
AnswerA

CloudFront cannot retrieve objects encrypted with SSE-C (Server-Side Encryption with Customer-Provided Keys) because it does not have a mechanism to store or pass the customer-provided encryption key to Amazon S3 during the object retrieval request. When CloudFront attempts to fetch such an object, S3 requires the encryption key as part of the request for decryption. Without the key, S3 denies access, resulting in a 403 Forbidden error, making SSE-C fundamentally incompatible with CloudFront's caching and distribution model.

Why this answer

The most likely cause is that the objects are encrypted with SSE-C. CloudFront cannot serve objects encrypted with SSE-C because it does not have the encryption key. When CloudFront requests such objects from S3, S3 returns a 403 Forbidden error.

The other options are incorrect: Option B is wrong because the OAC is correctly configured; Option C is wrong because the bucket policy allows the CloudFront service principal; Option D is wrong because using the S3 website endpoint would not cause a 403 for encrypted objects—it would cause a different error or redirect.

29
MCQhard

A company uses AWS CodePipeline with CodeBuild to deploy a Node.js application. The build fails intermittently with 'npm ERR! network' errors. What is the most likely cause and solution?

A.A unit test is failing; fix the test code.
B.The npm cache is corrupted; clear the cache in CodeBuild.
C.The build environment lacks outbound internet access; configure a NAT gateway or use a VPC endpoint for npm.
D.The npm token has expired; regenerate the token.
AnswerC

An ECONNRESET error signifies that the remote server unexpectedly closed the connection, often due to the client's inability to establish or maintain network connectivity. For CodeBuild projects running in a private VPC subnet, outbound internet access is crucial for npm install to fetch packages from public registries. Configuring a NAT Gateway in a public subnet or utilizing a VPC endpoint for specific services like S3 (if npm packages are stored there) provides the necessary outbound path, resolving such network-related build failures.

Why this answer

The 'npm ERR! network' error indicates that npm cannot reach the registry to download packages. If AWS CodeBuild is configured to run inside a VPC, it requires outbound internet access to reach the public npm registry. If CodeBuild is configured with multiple subnets and some of them lack a route to a NAT gateway, the builds will fail intermittently depending on which subnet the build container is provisioned in.

To resolve this, ensure all configured subnets have a route to a NAT gateway, or host your packages in AWS CodeArtifact and use a VPC endpoint to access them privately.

Exam trap

Candidates often assume 'npm ERR! network' is always a local cache or token issue, overlooking the VPC networking configuration. Another trap is forgetting that CodeBuild in a VPC requires a NAT gateway for internet access, and misconfiguring routing in even one of the selected subnets will cause intermittent build failures.

How to eliminate wrong answers

Option A is wrong because unit test failures produce different error messages (e.g., 'Test failed' or assertion errors), not 'npm ERR! network'. Option B is wrong because a corrupted npm cache would cause 'npm ERR! cache' or checksum errors, not network errors; clearing the cache would not resolve a connectivity issue. Option D is wrong because an expired npm token would result in 'npm ERR! code E401' or 'Unauthorized' errors, not network errors.

30
Multi-Selecteasy

A developer is troubleshooting a slow Amazon RDS for MySQL database. The application experiences high latency on write operations. Which TWO actions can improve write performance?

Select 2 answers
A.Add a read replica to offload read traffic.
B.Increase the allocated storage size to get better I/O performance.
C.Enable deletion protection.
D.Increase the DB instance class to a larger size.
E.Enable Multi-AZ deployment for high availability.
AnswersB, D

Increasing the allocated storage size, particularly for General Purpose SSD (gp2) volumes, directly improves I/O performance because throughput and IOPS scale with storage capacity. Larger gp2 volumes provide a higher baseline IOPS and accumulate I/O credits faster, enabling sustained burst performance and mitigating I/O bottlenecks. This ensures the database can read and write data to disk more efficiently, which is critical for write-intensive workloads.

Why this answer

Option B is correct because Amazon RDS storage performance is tied to the allocated storage size: increasing the allocated storage (especially into higher gp2/gp3 or io1/io2 tiers) raises the available IOPS and throughput, which directly reduces write latency. Option D is correct because moving to a larger DB instance class provides more vCPU, memory, and dedicated EBS bandwidth, allowing the database to process write operations faster and relieve resource contention. Option A is not correct because a read replica only offloads read traffic and does not improve write performance on the primary.

Option C is not correct because deletion protection is a safety feature that prevents accidental deletion and has no effect on I/O performance. Option E is not correct because Multi-AZ provides high availability via synchronous standby replication, not write performance improvement; in fact, it can add slight write overhead.

Exam trap

Candidates often mistakenly believe that enabling Multi-AZ (Option E) or adding Read Replicas (Option A) will help with write performance. In reality, Multi-AZ increases write latency due to synchronous replication, and Read Replicas only scale read operations.

31
MCQmedium

A developer runs the AWS CLI command shown in the exhibit. The output includes 'FunctionError': 'Unhandled'. What does this indicate?

A.The function threw an error that was caught by the code.
B.The function timed out.
C.The function threw an unhandled exception.
D.The function was not invoked successfully.
AnswerC

'FunctionError': 'Unhandled' is set by the Lambda runtime whenever the function code throws or rejects an exception that isn't caught anywhere in the handler, meaning the error propagated all the way up and terminated the invocation.

Why this answer

'Unhandled' indicates that the function code threw an exception that was not caught by any try-catch block. Option A is incorrect because a caught error would typically result in a 'Handled' status in the function logs, not 'Unhandled'. Option B is incorrect because a timeout error would produce a different error message, such as 'Task timed out', not 'Unhandled'.

Option D is incorrect because an invocation failure (e.g., permissions or configuration issues) would result in an error before the function runs, not an 'Unhandled' function error.

32
MCQhard

A developer is using Amazon API Gateway with a Lambda authorizer to control access to APIs. The authorizer is failing with a 500 error. The Lambda function logs show 'User: arn:aws:iam::123456789012:role/MyLambdaRole is not authorized to perform: sts:AssumeRole'. What is the most likely cause?

A.The Lambda authorizer is not returning a valid policy.
B.The Lambda function's resource-based policy is missing.
C.The API Gateway does not have permission to invoke the Lambda function.
D.The Lambda function's execution role does not have sts:AssumeRole permission for the target role.
AnswerD

The error message "AssumeRole permission denied" directly indicates that the AWS Lambda function, during its execution, attempted to call the AWS Security Token Service (STS) AssumeRole API operation to temporarily assume another IAM role, but its own execution role lacked the necessary sts:AssumeRole permission for that specific target role. The Lambda execution role defines what permissions the function has to interact with other AWS services. Without sts:AssumeRole explicitly granted for the target role in its policy, the function cannot obtain temporary credentials to perform actions under that role's permissions, leading to this specific authorization failure.

Why this answer

The error message indicates that the Lambda function's execution role (MyLambdaRole) attempted to call sts:AssumeRole but was denied. This occurs when the Lambda function's code tries to assume another IAM role (e.g., to access a resource in another account or service) but the execution role lacks the necessary sts:AssumeRole permission for that target role. Option D correctly identifies this root cause.

Option A is incorrect because an invalid policy from the authorizer would generate a different error (e.g., 403 or 401). Option B is incorrect because resource-based policies are for granting cross-account access to the Lambda function, not for assuming roles. Option C is incorrect because while API Gateway needs permission to invoke the Lambda function, a missing invoke permission would cause a different error (e.g., 500 with 'The API Gateway is not authorized to invoke the Lambda function'), not an sts:AssumeRole error.

33
Multi-Selecteasy

A web application running on Amazon EC2 instances behind an Application Load Balancer (ALB) is experiencing intermittent 503 errors. Which TWO steps should be taken to diagnose the issue?

Select 2 answers
A.Check the Route 53 health checks for the domain.
B.Check the CPU utilization of the EC2 instances.
C.Check the target group health check settings and instance health status.
D.Check the security group rules for the ALB.
E.Check the EBS volume type of the EC2 instances.
AnswersB, C

High CPU utilization on EC2 instances can severely impact their ability to process requests and respond to health checks in a timely manner. If instances are consistently overloaded, they may fail the Application Load Balancer's (ALB) health checks, causing the ALB to mark them as unhealthy. Consequently, the ALB will stop routing traffic to these instances and return 503 Service Unavailable errors to clients, as it has no healthy targets to forward requests to.

Why this answer

High CPU utilization on EC2 instances can cause them to become unresponsive or fail to respond to health checks within the ALB's configured timeout, leading to 503 errors. The ALB routes traffic only to healthy targets; if instances are overwhelmed, they may fail health checks or drop requests, resulting in a 503 response to clients.

Exam trap

The trap here is that candidates may confuse Route 53 health checks (DNS-level) with ALB target group health checks (application-level), or assume that security groups or EBS volumes are the root cause of HTTP 503 errors when they are not directly related to load balancer routing failures.

34
MCQmedium

An application running on Amazon ECS with Fargate is experiencing high latency. The application writes logs to Amazon CloudWatch Logs. Which AWS service can be used to analyze the logs to pinpoint the cause of the latency?

A.Amazon CloudWatch Logs
B.Amazon CloudWatch Logs Insights
C.AWS X-Ray
D.Amazon S3
AnswerB

Amazon CloudWatch Logs Insights is specifically designed for interactively searching, analyzing, and visualizing log data to troubleshoot operational problems and identify performance bottlenecks. It allows users to run powerful queries using a purpose-built query language to filter, aggregate, and extract specific information from log events, making it ideal for pinpointing the root causes of latency within application logs. This direct analytical capability is crucial for diagnosing issues.

Why this answer

Amazon CloudWatch Logs Insights is the correct choice because it is purpose-built for interactively querying and analyzing log data stored in CloudWatch Logs. It allows you to run SQL-like queries (using a query language) to filter, aggregate, and visualize log events, which is essential for pinpointing latency patterns, such as slow API calls or database queries, without needing to export logs to another service.

Exam trap

The trap here is that candidates confuse CloudWatch Logs (storage/monitoring) with CloudWatch Logs Insights (query/analysis), assuming the former can perform deep log analysis, when in fact it only supports basic metric filters and real-time monitoring.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch Logs itself is a log storage and monitoring service, not a query engine; it can only view raw log streams or set metric filters, not perform ad-hoc analytical queries to diagnose latency. Option C is wrong because AWS X-Ray is a distributed tracing service that traces requests through microservices, but it does not analyze CloudWatch Logs; it uses its own trace data and segments, not log files. Option D is wrong because Amazon S3 is an object storage service; while logs can be exported to S3, it provides no built-in querying capability for log analysis without additional services like Athena.

35
MCQhard

An application running on Amazon ECS (Fargate) uses an Application Load Balancer (ALB) with connection draining enabled. The application is experiencing intermittent 502 (Bad Gateway) errors during rolling updates of the ECS service. The developer notices that the ALB is routing requests to tasks that are in the 'Draining' state. The ECS service is configured with a deployment circuit breaker that automatically rolls back a failed deployment. What is the most likely cause of the 502 errors?

A.The ALB's idle timeout is too short, causing connections to be dropped before the application responds.
B.The ALB's connection draining timeout is set to 0 seconds, causing connections to be dropped immediately when deregistering targets.
C.The ECS deployment circuit breaker is incorrectly configured to roll back on health check failures.
D.The application is not handling the SIGTERM signal from ECS, causing it to terminate abruptly while the ALB still routes traffic to it.
AnswerD

When ECS stops a task, it sends a SIGTERM signal to allow the application to gracefully shut down. If the application does not catch this signal and stop accepting new connections or complete in-flight requests before exiting, the ALB may still send traffic to the task after it stops, resulting in 502 errors. This is a common issue during rolling updates.

Why this answer

When ECS sends a SIGTERM signal to a Fargate task during a rolling update, the task is expected to gracefully shut down. If the application does not handle SIGTERM, it terminates immediately, but the ALB may still have the task registered as a target and continue routing requests to it. Since the task is already dead or unresponsive, the ALB receives no valid HTTP response and returns a 502 Bad Gateway error.

Connection draining is enabled, but it only works if the task signals the ALB that it is deregistering; without proper SIGTERM handling, the task dies before the draining process completes.

Exam trap

The trap here is that candidates often assume connection draining is a silver bullet that prevents all errors during rolling updates, but they overlook that the application must handle SIGTERM to allow the draining process to work as intended.

How to eliminate wrong answers

Option A is wrong because the ALB's idle timeout (default 60 seconds) controls how long the ALB keeps a connection open without data transfer; it does not cause 502 errors during rolling updates, as 502s stem from the target not responding, not from idle timeouts. Option B is wrong because setting connection draining timeout to 0 seconds would cause immediate deregistration, which would prevent routing to draining tasks, not cause 502 errors; the problem here is that tasks are still receiving traffic while draining, which is the opposite scenario. Option C is wrong because the deployment circuit breaker rolls back the entire deployment on health check failures, but it does not cause 502 errors during the update; it is a recovery mechanism, not a root cause of the errors.

36
MCQmedium

A developer monitors an AWS Lambda function that processes messages from an Amazon SQS queue. CloudWatch logs show that the function's execution time has increased significantly over the past week, and it now frequently times out at the 5-minute timeout. The function's code has not been changed recently. The function makes calls to an Amazon DynamoDB table. What is the most likely cause of the increased execution time?

A.The DynamoDB table's read capacity units are underprovisioned, causing throttling.
B.The SQS queue's visibility timeout is too short, causing duplicate processing.
C.The Lambda function's memory is too low, causing CPU throttling.
D.The DynamoDB table's indexes are missing, causing full table scans.
AnswerA

When a Lambda function attempts to read from a DynamoDB table with insufficient Read Capacity Units (RCUs), DynamoDB will throttle the requests. This throttling results in ProvisionedThroughputExceededException errors, forcing the Lambda function to implement retry logic, which significantly prolongs its execution time. Repeated retries against a persistently throttled table can cause the function to approach or exceed its configured timeout, indicating a clear resource bottleneck.

Why this answer

The most likely cause is that the DynamoDB table's read capacity units are underprovisioned, leading to throttling (ProvisionedThroughputExceededException). When DynamoDB throttles requests, the Lambda function must retry them, which adds latency and can cause the function to exceed its 5-minute timeout. Since the code hasn't changed, this points to a scaling or capacity issue on the DynamoDB side.

Exam trap

The trap here is that candidates may confuse DynamoDB throttling with Lambda timeout configuration, overlooking that gradual performance degradation often points to downstream resource contention rather than function configuration.

How to eliminate wrong answers

Option B is wrong because a short SQS visibility timeout would cause duplicate processing, not increased execution time; duplicates would result in more invocations, not slower individual runs. Option C is wrong because low memory in Lambda causes CPU throttling only if the function is CPU-bound; memory allocation affects CPU proportionally, but the described symptom (increased execution time without code changes) is not typically caused by memory alone. Option D is wrong because missing indexes would cause full table scans, which would increase execution time from the start, not gradually over a week; this would be a code or schema issue, not a gradual degradation.

37
MCQhard

A developer deployed a new version of an AWS Lambda function that is part of a serverless application. The function uses an Amazon DynamoDB table as a data store. After deployment, the developer notices that the function's latency has increased significantly for some requests. CloudWatch traces show that the increase is due to DynamoDB throttle events. The function is configured with a reserved concurrency of 100 and the DynamoDB table has 5 read capacity units (RCUs) and 5 write capacity units (WCUs). What is the most effective way to reduce the throttling while maintaining application performance?

A.Decrease the reserved concurrency of the Lambda function to 10
B.Increase the read and write capacity units on the DynamoDB table
C.Enable DynamoDB Accelerator (DAX) for caching reads
D.Enable auto scaling on the DynamoDB table
AnswerB

Increasing the read and write capacity units (RCU/WCU) on the DynamoDB table directly raises its maximum sustained throughput. These units define the number of strongly consistent reads and 1KB writes the table can handle per second. By provisioning more capacity, the table can accommodate a higher volume of operations, directly mitigating throttling errors that occur when request rates exceed the current limits.

Why this answer

The primary cause of the throttling is insufficient DynamoDB capacity to handle the request volume from the Lambda function. Increasing the read and write capacity units (RCUs/WCUs) directly addresses the throttle events by providing more throughput to match the function's concurrency of 100. This is the most effective solution because it resolves the bottleneck at the data store level without reducing the application's ability to process requests concurrently.

Exam trap

The trap here is that candidates may choose auto scaling (Option D) thinking it dynamically handles spikes, but they overlook that auto scaling has a significant lag and cannot prevent immediate throttling, whereas increasing the base capacity is the immediate and effective solution.

How to eliminate wrong answers

Option A is wrong because decreasing reserved concurrency to 10 would reduce the number of concurrent Lambda invocations, which would lower the request rate to DynamoDB and potentially reduce throttling, but it would also severely degrade application performance by limiting throughput and increasing latency for legitimate traffic. Option C is wrong because DynamoDB Accelerator (DAX) is an in-memory cache that only accelerates read operations (GetItem, Query, Scan) and does not help with write throttling or reduce write capacity consumption; the question does not specify that the throttling is read-only, and DAX cannot mitigate write capacity throttling. Option D is wrong because enabling auto scaling on the DynamoDB table would adjust capacity over time based on traffic patterns, but it cannot react instantly to sudden spikes in demand; auto scaling has a lag of several minutes, so it would not prevent the immediate throttle events that are already occurring, and it does not address the need for a higher baseline capacity to match the Lambda's concurrency.

38
MCQmedium

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB). Users report intermittent 503 errors. The ALB health checks are failing for a few instances, but the instances themselves are running and have healthy application processes. What is the MOST likely cause?

A.The ALB is not scaled to handle the traffic.
B.The security group for the EC2 instances is not allowing traffic from the ALB.
C.The DNS resolution via Route53 is misconfigured.
D.Sticky sessions are not enabled on the ALB.
AnswerB

The security group associated with the EC2 instances acts as a virtual firewall, controlling inbound and outbound traffic. For ALB health checks to succeed, the EC2 instance's security group must have an inbound rule that explicitly permits traffic from the ALB's security group or its private IP range on the health check port. If this rule is missing or misconfigured, the ALB's health check probes will be blocked at the network level, preventing a successful connection and causing the ALB to mark the instance as unhealthy.

Why this answer

The ALB health checks are failing despite the instances and application processes being healthy, which indicates a network-level issue. The most likely cause is that the EC2 instances' security group is not allowing inbound traffic from the ALB's security group on the health check port (e.g., HTTP/HTTPS). Without this rule, the ALB cannot reach the health check endpoint, marking the instances as unhealthy and causing intermittent 503 errors when traffic is routed to those instances.

Exam trap

The trap here is that candidates often assume health check failures are always due to application issues (e.g., process crashes) rather than network-layer misconfigurations like security group rules, especially when the instance appears healthy from within the OS.

How to eliminate wrong answers

Option A is wrong because the ALB scales automatically based on traffic patterns and does not require manual scaling; 503 errors from insufficient capacity would be persistent, not intermittent, and would affect all instances. Option C is wrong because DNS misconfiguration via Route53 would cause resolution failures (e.g., NXDOMAIN) or routing to the wrong endpoint, not intermittent 503 errors from healthy instances behind an ALB. Option D is wrong because sticky sessions (session affinity) do not affect health checks or 503 errors; they only control how requests are distributed to the same target, and their absence would not cause health check failures.

39
MCQhard

A developer receives an Access Denied error when trying to download an object from an S3 bucket. The developer's IAM policy is shown in the exhibit. The bucket policy also grants access. What is the MOST likely cause?

A.The S3 bucket has block public access enabled.
B.The S3 bucket uses SSE-KMS and the user lacks kms:Decrypt permission.
C.The IAM policy does not allow s3:GetObject.
D.The bucket policy denies access to the user.
AnswerB

When an object is encrypted with SSE-KMS, retrieving it requires not only s3:GetObject permission on the object but also kms:Decrypt permission on the specific KMS key used to encrypt it; if the IAM policy grants only the S3 action and omits the KMS action, the decrypt call fails and S3 surfaces this as an Access Denied error even though the S3-level permissions look correct.

Why this answer

If the bucket is encrypted with a KMS key, the user must also have kms:Decrypt permission. Option A is wrong because the policy explicitly allows s3:GetObject. Option C is wrong because the bucket policy also grants access, so it's not a bucket policy issue.

Option D is wrong because public access is not required if IAM policies allow access.

40
MCQhard

A developer is troubleshooting an AWS Lambda function that experiences high latency for the first few invocations after being idle. The function is written in Python and uses a large library (e.g., Pandas). The function connects to an RDS database in a VPC. What is the most effective way to reduce the latency for the first invocation after idle?

A.Increase the function's memory allocation to 3008 MB.
B.Enable provisioned concurrency on the function.
C.Move the large library to a Lambda layer.
D.Replace the RDS database with Amazon DynamoDB.
AnswerB

Provisioned concurrency pre-initializes a specified number of execution environments for a Lambda function, ensuring they are ready to process requests immediately. This effectively eliminates cold start latency for invocations routed to these pre-warmed instances, as the entire initialization phase (including code download, runtime bootstrapping, and `init` code execution) has already completed. It guarantees consistently low latency for critical, latency-sensitive applications by maintaining a pool of ready-to-go containers.

Why this answer

Provisioned concurrency keeps a specified number of execution environments initialized and ready to respond immediately, eliminating the cold start latency that occurs after a period of idle time. This is the most direct solution for reducing latency on the first invocation after idle, especially for functions with large libraries like Pandas that take significant time to load.

Exam trap

The trap here is that candidates often confuse cold start mitigation strategies like increasing memory or using layers with the only AWS feature that truly eliminates cold starts for idle functions: provisioned concurrency.

How to eliminate wrong answers

Option A is wrong because increasing memory allocation can improve CPU performance and reduce cold start time slightly, but it does not eliminate the cold start itself; the function still needs to load the large library and establish the VPC connection from scratch after idle. Option C is wrong because moving the library to a Lambda layer does not reduce cold start latency; layers are simply a packaging mechanism and the library still must be loaded into memory during initialization. Option D is wrong because replacing RDS with DynamoDB addresses database connection latency, not the cold start latency caused by loading the large Python library and initializing the function runtime.

41
MCQmedium

A developer notices that an AWS Lambda function processing S3 events is being retried frequently due to throttling errors from Amazon DynamoDB. The function writes records to a DynamoDB table and has reserved concurrency set to 100. The DynamoDB table uses on-demand capacity mode. What should the developer do to reduce retries and improve overall throughput?

A.Increase the Lambda function's reserved concurrency to 500.
B.Implement exponential backoff and retry in the Lambda function code for DynamoDB API calls.
C.Disable the Lambda function's S3 event source mapping and use Amazon SQS to buffer events.
D.Switch the DynamoDB table to provisioned capacity with a high write capacity unit setting.
AnswerB

Implementing exponential backoff and retry in the Lambda function code for DynamoDB API calls is the most effective solution. This pattern automatically handles transient errors like throttling by retrying failed requests with progressively longer delays between attempts. This approach allows DynamoDB time to recover from temporary capacity constraints, significantly increasing the success rate of API calls without overwhelming the database, thus making the Lambda function more resilient.

Why this answer

Implementing exponential backoff and retry in the Lambda function code for DynamoDB API calls directly addresses the throttling errors. Even with on-demand capacity, DynamoDB can throttle requests if they exceed the table's burst capacity or if there are hot partitions. Exponential backoff reduces the retry rate, allowing DynamoDB to recover and improving overall throughput without changing the Lambda concurrency or capacity mode.

Exam trap

The trap here is that candidates assume increasing Lambda concurrency or switching to provisioned capacity will solve throttling, but the real issue is the retry strategy at the application layer, not the infrastructure scaling.

How to eliminate wrong answers

Option A is wrong because increasing reserved concurrency to 500 would only increase the number of concurrent Lambda invocations, which would exacerbate DynamoDB throttling by sending more requests simultaneously. Option C is wrong because disabling the S3 event source mapping and using SQS to buffer events would add latency and complexity but does not address the root cause of DynamoDB throttling; it only decouples the invocation, not the write errors. Option D is wrong because switching to provisioned capacity with a high write capacity unit setting does not guarantee elimination of throttling; on-demand mode already scales automatically, and the issue is likely due to request patterns or hot partitions, not capacity mode.

42
MCQeasy

A developer is troubleshooting an AWS Lambda function that is failing with an 'AccessDenied' error when trying to write to an S3 bucket. The function's execution role has the following policy. What is the most likely cause of the failure? (Policy: { 'Version': '2012-10-17', 'Statement': [ { 'Effect': 'Allow', 'Action': 's3:PutObject', 'Resource': 'arn:aws:s3:::my-bucket/*' } ] })

A.The resource ARN does not include the bucket itself; it only includes objects
B.The S3 bucket has a bucket policy that denies the Lambda role access.
C.The action 's3:PutObject' is not allowed for Lambda execution roles
D.The action 's3:PutObject' is not sufficient; need 's3:*'
AnswerB

AWS policy evaluation logic dictates that an explicit `Deny` statement in any policy always overrides an `Allow` statement, even if the `Allow` is present in an identity-based policy attached to the Lambda execution role. If the S3 bucket's resource policy explicitly denies the Lambda role access for `s3:PutObject`, this denial will take precedence, preventing the Lambda function from uploading objects despite its own role permissions. This is a common security control for resource owners.

Why this answer

The IAM policy attached to the Lambda execution role correctly allows s3:PutObject on the bucket's objects. However, when a bucket policy explicitly denies access to the role or does not grant the required permissions, it takes precedence over the identity-based policy, resulting in an 'AccessDenied' error. Therefore, the most likely cause is a restrictive bucket policy.

Exam trap

Candidates often focus solely on the identity-based policy and forget that a bucket policy can override it. Even with a correctly scoped role policy, a bucket policy denying access will cause AccessDenied.

43
MCQhard

The exhibit shows an IAM policy attached to a Lambda function's execution role. The function writes objects to an S3 bucket that is encrypted with a KMS key (the key specified in the policy). When the function tries to write an object, it receives an access denied error. What is the MOST likely missing permission?

A.kms:GenerateDataKey is missing.
B.The KMS key policy does not allow the Lambda function role.
C.s3:GetObject is missing for the bucket.
D.kms:ReEncrypt is missing.
AnswerA

When S3 performs server-side encryption with AWS KMS (SSE-KMS), it requires the calling principal, such as the Lambda function's execution role, to have the kms:GenerateDataKey permission. This specific permission allows S3 to request a unique data key from KMS to encrypt the object data itself. Without this crucial permission, S3 cannot obtain the necessary encryption key to perform the server-side encryption during the PutObject operation, leading to a failure.

Why this answer

When writing an object to an S3 bucket encrypted with SSE-KMS, the caller must have kms:GenerateDataKey permission so S3 can obtain a data key to encrypt the object. Without it, the write fails with AccessDenied even if s3:PutObject is granted. The other options either describe a different failure mode or a permission not required for a simple PutObject.

Exam trap

DVA-C02 often tests the misconception that S3 permissions alone are sufficient for encrypted buckets — candidates forget that SSE-KMS writes also require kms:GenerateDataKey (and reads require kms:Decrypt).

How to eliminate wrong answers

Option B is wrong because while the KMS key policy must allow the role, the question states the key is specified in the policy and the error is about a missing permission — the most likely cause is a missing IAM action, not a key policy issue (and key policy problems would typically be described differently). Option C is wrong because s3:GetObject is needed for reading objects, not writing them; the function is performing a write. Option D is wrong because kms:ReEncrypt is used when re-encrypting data between keys, which is not part of a standard S3 PutObject with SSE-KMS.

44
MCQmedium

A developer is running a Docker container on Amazon ECS with Fargate. The container logs are not appearing in CloudWatch Logs even though the task definition has a logConfiguration specifying the awslogs driver and a log group. What is the MOST likely missing configuration?

A.The container image does not have the awslogs log driver installed.
B.The task execution role lacks the necessary IAM permissions to write to CloudWatch Logs.
C.The CloudWatch Logs log group does not exist.
D.The EC2 instance profile does not have CloudWatch Logs permissions.
AnswerB

For an Amazon ECS task to successfully send container logs to CloudWatch Logs, the assigned Task Execution IAM role must possess specific permissions. These include logs:CreateLogStream to create the necessary log stream within the specified log group and logs:PutLogEvents to write log data to that stream. Without these critical permissions, the ECS agent will be unable to interact with CloudWatch Logs, resulting in logging failures.

Why this answer

For Fargate tasks, the awslogs driver uses the task execution role (not the task role) to call logs:CreateLogStream and logs:PutLogEvents. If that role lacks these permissions, the container starts but log delivery silently fails, which is the most common cause of missing CloudWatch logs.

Exam trap

DVA-C02 often tests the confusion between the task execution role and the task role — candidates pick 'execution role lacks permissions' correctly only if they know the awslogs driver runs under the execution role, not the application task role.

How to eliminate wrong answers

Option A is wrong because the awslogs driver is built into the ECS/Fargate agent and Docker daemon — it is not something installed in the container image. Option C is wrong because ECS auto-creates the log group if it does not exist, and a missing group would not be the 'most likely' cause when the task definition already specifies one. Option D is wrong because Fargate has no EC2 instance profile; that concept applies only to EC2 launch type tasks.

45
MCQhard

A developer notices that an AWS Lambda function, which processes messages from an SQS queue, is taking longer than expected. The function has a reserved concurrency of 5 and a batch size of 10. The SQS queue has a large backlog. CloudWatch metrics show that the function's throttles are high. The function is idempotent and can process up to 100 messages per invocation. What is the most effective way to increase throughput without increasing reserved concurrency?

A.Increase the batch size to 100.
B.Increase reserved concurrency to 10.
C.Change the function timeout to 15 minutes.
D.Enable SQS short polling to reduce latency.
AnswerA

By increasing the SQS batch size to 100, the Lambda function processes up to 100 messages in a single invocation. Since the function is capable of handling this volume, this optimization significantly reduces the total number of Lambda invocations required to process a given message backlog. Fewer invocations directly translate to a lower invocation rate, effectively alleviating the throttling issues experienced by the function and optimizing resource utilization.

Why this answer

Increasing the batch size to 100 directly reduces the number of Lambda invocations required to process the backlog, thereby decreasing throttling without increasing reserved concurrency. The function's capacity to handle up to 100 messages per invocation makes this alignment optimal. SQS event source mappings support batch sizes up to 10,000 for standard queues, so a batch size of 100 is feasible.

Short polling (option D) would not improve throughput; it causes frequent empty responses and does not reduce throttling. Increasing reserved concurrency violates the constraint, and changing timeout (option C) does not address throttling.

Exam trap

A common pitfall is assuming that Lambda's SQS batch size is limited to 10. In fact, for standard queues the maximum is 10,000. Since the function can process up to 100 messages per invocation, increasing the batch size to 100 directly increases throughput without increasing reserved concurrency.

Candidates may also incorrectly consider increasing reserved concurrency, which is explicitly outside the scope of the question.

How to eliminate wrong answers

Option B is wrong because increasing reserved concurrency would increase the number of concurrent executions, which directly contradicts the requirement to not increase reserved concurrency. Option C is wrong because increasing the function timeout does not increase throughput; it only allows longer processing time per invocation, but the bottleneck is throttling due to concurrency limits, not execution duration. Option D is wrong because enabling SQS short polling reduces latency for message retrieval but does not increase the number of messages processed per invocation or reduce throttling; it may even increase the number of empty responses.

46
MCQhard

An application running on Amazon ECS Fargate is experiencing intermittent high latency and timeout errors. The application makes API calls to an external third-party service. The ECS service is configured with a target group using HTTP health checks. The ALB health check logs show occasional 503 responses. What is the MOST likely cause?

A.The security group for the ECS tasks is blocking inbound traffic from the ALB.
B.The ECS tasks are running out of CPU credits, causing slow response times.
C.The ECS service is configured with a task placement strategy that is causing tasks to be stopped and restarted frequently.
D.The application is not properly handling timeouts to the third-party service, causing the health check endpoint to hang.
AnswerD

When an application's health check endpoint makes a synchronous call to a third-party service without proper timeout handling, a slow or unresponsive external dependency can cause the health check to hang indefinitely. This prolonged unresponsiveness will eventually exceed the Application Load Balancer's configured health check timeout threshold. Consequently, the ALB will mark the task as unhealthy and return a 503 error for requests routed to it, leading to intermittent service disruptions as tasks are cycled.

Why this answer

The application's health check endpoint is likely hanging because the application does not handle timeouts when calling the third-party service. This causes the ALB health check to time out and return 503, leading to tasks being marked unhealthy and potentially restarted, which increases latency and timeouts.

Exam trap

DVA-C02 often tests the difference between infrastructure misconfigurations and application-level issues. Candidates may jump to security groups or CPU credits, but the intermittent nature and 503s on health checks point to application timeouts. Also, Fargate does not have CPU credits, which is a common distractor.

How to eliminate wrong answers

Option A is wrong because if the security group blocked inbound traffic from the ALB, the health checks would consistently fail, not intermittently. Option B is wrong because Fargate tasks do not use CPU credits; that is an EC2 burstable instance concept. Option C is wrong because a task placement strategy causing frequent restarts would likely show tasks stopping and starting, but the symptom of intermittent 503s on health checks points to application-level hangs.

47
MCQeasy

A developer notices that an S3 bucket used for static website hosting returns 403 Forbidden for anonymous requests. The bucket policy allows s3:GetObject for Principal "*". What is the most likely issue?

A.The bucket does not have server access logging enabled.
B.The bucket ACL does not allow public read.
C.The bucket policy is not attached to the correct bucket.
D.The S3 Block Public Access settings are enabled.
AnswerD

Amazon S3 Block Public Access settings provide a crucial security control designed to prevent unintended public exposure of S3 buckets and objects. These settings, configurable at both the account and bucket level, explicitly override all other access control mechanisms, including permissive bucket policies and object ACLs, that would otherwise grant public access. If these Block Public Access settings are enabled, they will effectively block all public access to the static website, regardless of any correctly configured bucket policies or ACLs intended to allow public reads.

Why this answer

D is correct because S3 Block Public Access settings, when enabled at the account or bucket level, override any bucket policy or ACL that grants public access. Even though the bucket policy allows s3:GetObject for Principal "*", the Block Public Access settings explicitly deny all public requests, resulting in a 403 Forbidden error for anonymous users.

Exam trap

The trap here is that candidates often assume a bucket policy granting public access is sufficient, overlooking the S3 Block Public Access settings which silently override such policies and cause 403 errors.

How to eliminate wrong answers

Option A is wrong because server access logging is a feature for logging requests to the bucket, not a permission control; it does not affect whether requests are allowed or denied. Option B is wrong because the bucket policy already grants public read access via Principal "*", and while ACLs can also grant public read, the bucket policy takes precedence; the issue is not the ACL but an overriding deny. Option C is wrong because the question states the bucket policy is attached and allows s3:GetObject, so the policy is correctly associated; the problem lies with a separate security mechanism.

48
MCQhard

A company runs a monolithic application on EC2 Behind an Application Load Balancer. They want to migrate to a microservices architecture using ECS Fargate. What is the most important optimization to ensure minimal downtime during the migration?

A.Use a blue/green deployment strategy with weighted target groups.
B.Increase the EC2 instance size to handle the microservices load.
C.Deploy all microservices in a single ECS service for simplicity.
D.Scale horizontally by adding more EC2 instances.
AnswerA

A blue/green deployment strategy is ideal for migrating a monolithic application to microservices with minimal downtime. It involves running two identical environments: the existing 'blue' version and the new 'green' version with microservices. Weighted target groups, typically configured on an Application Load Balancer (ALB) or Route 53, allow for a controlled, gradual shift of traffic from the blue to the green environment, enabling real-time testing and easy rollback if issues occur.

Why this answer

A blue/green deployment strategy with weighted target groups allows you to gradually shift traffic from the existing monolithic EC2 application (blue) to the new microservices on ECS Fargate (green) while monitoring for errors. This minimizes downtime by enabling instant rollback if issues arise, and it leverages Application Load Balancer (ALB) features like stickiness and health checks to ensure a seamless transition without disrupting active connections.

Exam trap

The trap here is that candidates confuse scaling strategies (horizontal/vertical) with deployment strategies, assuming that adding more capacity or consolidating services will inherently reduce downtime, when in fact only a controlled traffic-shifting method like blue/green with weighted routing ensures minimal disruption during a live migration.

How to eliminate wrong answers

Option B is wrong because increasing EC2 instance size does not address the migration to microservices or ECS Fargate; it only scales the monolithic application vertically, which contradicts the goal of moving to a serverless container architecture and does not reduce downtime during migration. Option C is wrong because deploying all microservices in a single ECS service defeats the purpose of microservices isolation, scaling, and independent deployment; it introduces tight coupling and increases the blast radius of failures, leading to higher downtime risk. Option D is wrong because scaling horizontally by adding more EC2 instances only scales the monolithic application, not the microservices on Fargate, and does not provide a controlled traffic-shifting mechanism to minimize downtime during migration.

49
MCQmedium

A developer configured an S3 bucket to trigger a Lambda function on object creation. The Lambda function processes the object and then deletes it. Some objects are not being processed. What should the developer do to ensure all objects are processed?

A.Assign a new IAM role to the Lambda function with S3 permissions.
B.Enable S3 versioning on the bucket.
C.Send S3 events to an SQS queue and configure the Lambda function to poll the queue.
D.Increase the Lambda function timeout.
AnswerC

Direct S3-to-Lambda invocations are 'at-least-once' but can occasionally miss events under specific conditions or if the Lambda invocation fails without successful retry. By sending S3 events to an SQS queue first, SQS acts as a durable buffer, ensuring messages are reliably stored and can be retried if the Lambda function fails to process them. The Lambda function then polls the SQS queue, pulling messages and processing them, leveraging SQS's built-in retry mechanisms and dead-letter queue capabilities for robust event handling and guaranteed delivery.

Why this answer

Sending S3 events to an SQS queue decouples event delivery from Lambda invocation. If the Lambda function fails or throttles, the event remains in the queue and can be retried, ensuring no objects are missed. Without a queue, S3 events that fail to invoke Lambda (e.g., due to concurrency limits) are lost, leading to unprocessed objects.

Exam trap

The trap here is that candidates assume the issue is a permission or timeout problem, when in fact the root cause is the loss of S3 event notifications due to Lambda throttling or transient failures, which a queue-based architecture resolves.

How to eliminate wrong answers

Option A is wrong because the Lambda function already processes and deletes objects, so it must already have S3 permissions; assigning a new IAM role would not fix lost events. Option B is wrong because enabling S3 versioning preserves object versions but does not affect event delivery reliability or retry behavior. Option D is wrong because increasing the Lambda function timeout addresses execution duration, not the loss of events due to throttling or invocation failures.

50
MCQmedium

A developer is troubleshooting an AWS Lambda function that returns timeout errors when calling an external HTTPS API. The function is configured with a 30-second timeout and runs in a VPC with a public subnet and NAT Gateway. The developer checks CloudWatch logs and sees that the function is timing out at exactly 30 seconds. What is the most likely cause?

A.The NAT Gateway is not configured with a route to the internet.
B.The Lambda function's security group does not allow outbound traffic.
C.The external API's response time exceeds 30 seconds.
D.The Lambda function's VPC does not have an internet gateway.
AnswerB

This is the correct explanation. When a Lambda function is configured within a VPC, its network interfaces are subject to the associated security group rules. If the egress (outbound) rules of the security group do not explicitly permit traffic on the required port (e.g., HTTPS on port 443) to the external API's IP range or `0.0.0.0/0`, the connection attempt will be blocked. This blockage prevents the TCP handshake from completing, causing the function to wait indefinitely until its configured execution timeout is reached.

Why this answer

Lambda functions running in a VPC do not automatically get internet access; they require a route to a NAT Gateway or NAT instance. Even with a NAT Gateway, the Lambda function's security group must allow outbound traffic (e.g., HTTPS on port 443) to reach the external API. Without this rule, outbound packets are dropped, causing the function to hang until the configured timeout (30 seconds) expires, resulting in a timeout error.

Exam trap

The trap here is that candidates assume a NAT Gateway alone provides internet access to Lambda, overlooking that security group egress rules must explicitly allow outbound traffic to the destination.

How to eliminate wrong answers

Option A is wrong because the NAT Gateway is explicitly stated to be present, and a NAT Gateway requires a route to the internet (via an Internet Gateway) to function; if it were misconfigured, the function would likely fail immediately or at a different timeout, not exactly at 30 seconds. Option C is wrong because the function times out at exactly 30 seconds, matching its configured timeout, not at a variable time based on API response; if the API exceeded 30 seconds, the timeout would still occur at 30 seconds, but the question asks for the most likely cause given the VPC setup. Option D is wrong because the VPC does not need an Internet Gateway for outbound traffic through a NAT Gateway; the NAT Gateway itself resides in a public subnet and uses an Internet Gateway, but the Lambda function's VPC configuration is separate—the issue is security group egress rules, not the presence of an Internet Gateway.

51
MCQhard

A developer is troubleshooting performance issues in an application that uses Amazon DynamoDB as the primary data store. The application reads a large set of items using a Query operation on a Global Secondary Index (GSI). The developer notices high read latency and throttled requests on the GSI. The base table has sufficient read capacity. The GSI is projected with KEYS_ONLY. Which action would most likely reduce the latency and throttling?

A.Increase the read capacity units (RCU) of the base table.
B.Change the GSI projection to ALL.
C.Increase the read capacity units (RCU) of the GSI.
D.Create a Local Secondary Index instead.
AnswerC

Throttling on a Global Secondary Index (GSI) is a direct indication that its provisioned read capacity units (RCU) are insufficient to handle the current read request volume. Since GSIs have their own distinct capacity settings, increasing the RCU specifically for the GSI directly addresses this bottleneck. This action allows the index to process more read operations per second, thereby alleviating throttling and improving application performance and latency.

Why this answer

A Global Secondary Index (GSI) has its own provisioned read capacity, separate from the base table. When a Query operation reads from a GSI, it consumes RCUs from the GSI's capacity, not the base table's. Since the base table has sufficient read capacity but the GSI is experiencing throttling and high latency, increasing the GSI's RCU directly addresses the bottleneck by allowing more read requests per second against the index.

Exam trap

The trap here is that candidates often assume increasing the base table's capacity will resolve all read performance issues, failing to recognize that GSIs have independent capacity allocations and that throttling on a GSI requires adjusting the index's RCU, not the base table's.

How to eliminate wrong answers

Option A is wrong because increasing the base table's RCU does not affect the GSI's throughput; the GSI has its own independent capacity settings, and throttling on the GSI is caused by insufficient RCU on the index itself. Option B is wrong because changing the GSI projection to ALL would increase the size of each item returned, consuming more RCUs per query and potentially worsening latency and throttling, not reducing it. Option D is wrong because a Local Secondary Index (LSI) shares the base table's partition key and RCU/WCU, but it does not solve the issue of insufficient read capacity on the index; additionally, LSIs cannot be created after table creation if not initially defined, and they have different partition key constraints that do not address the GSI-specific throttling.

52
MCQeasy

A developer is troubleshooting an EC2 instance that cannot connect to the internet. The instance has a public IP address and is in a public subnet with a route to an internet gateway. The security group allows all outbound traffic. What is the most likely cause?

A.The subnet's route table does not have a route to an internet gateway.
B.The security group's outbound rules are too restrictive.
C.The network ACL's outbound rules are blocking traffic.
D.The instance does not have a public IP address.
AnswerC

Unlike security groups, network ACLs are stateless, meaning outbound and return inbound traffic must each be explicitly permitted by separate rule evaluations; if the outbound NACL rules block traffic to the internet, or the inbound rules fail to allow the ephemeral port range needed for return traffic, connectivity will fail even with a correctly configured route table and permissive security group.

Why this answer

Network ACLs are stateless and block traffic unless explicitly allowed. The security group allows all outbound traffic, but if the network ACL's outbound rules are too restrictive, traffic can be blocked. Option A is wrong because the subnet has a route to an internet gateway.

Option B is wrong because the security group allows all outbound traffic. Option D is wrong because the instance has a public IP address.

53
MCQhard

A developer is troubleshooting an AWS Lambda function that processes messages from an Amazon SQS queue. The function is configured with a batch size of 10 and a maximum concurrency of 5. The function frequently reports errors related to message processing timeouts. The function code is idempotent. Which combination of actions will reduce the number of timeouts and improve processing efficiency?

A.Increase the function timeout to 30 seconds and set the SQS visibility timeout to 6 minutes.
B.Increase the batch size to 20 and increase the function timeout to 30 seconds.
C.Reduce the batch size to 5 and increase the maximum concurrency to 10.
D.Increase the maximum concurrency to 10 and set the SQS visibility timeout to 30 seconds.
AnswerC

Reducing the SQS batch size to 5 messages per invocation decreases the amount of work each Lambda instance must perform, thereby lowering the execution time and reducing the likelihood of timeouts. Simultaneously, increasing the maximum concurrency to 10 allows more Lambda instances to run in parallel, effectively processing multiple smaller batches concurrently. This combination optimizes for faster individual processing while scaling out to maintain or improve overall message throughput.

Why this answer

Reducing the batch size to 5 decreases the number of messages processed per invocation, lowering the processing time and reducing the likelihood of timeouts. Increasing maximum concurrency to 10 allows more Lambda functions to run in parallel, improving overall throughput. Option A is wrong: increasing the Lambda timeout to 30 seconds alone does not address the root cause (overloaded invocations), and setting the SQS visibility timeout to 6 minutes may cause delayed retries if messages fail.

Option B is wrong: increasing the batch size to 20 would increase the processing time per invocation, exacerbating timeouts. Option D is wrong: increasing concurrency to 10 helps parallelism but does not reduce the per-invocation workload; setting visibility timeout to 30 seconds is too short, risking message duplication if processing exceeds that time.

54
Multi-Selectmedium

A company is using Amazon S3 to store large objects. Users report that uploads are slow. Which THREE actions should the developer take to optimize upload performance?

Select 3 answers
A.Use multipart upload for objects over 100 MB.
B.Use S3 Select to upload only specific parts of the object.
C.Enable S3 Transfer Acceleration.
D.Transition objects to S3 Glacier after upload.
E.Use multiple S3 prefixes to increase request rate.
AnswersA, C, E

Multipart upload splits a large object into independent parts that are uploaded in parallel, which dramatically increases throughput and enables efficient retries for individual failed parts. The AWS SDKs automatically apply multipart upload when an object exceeds the 100 MB threshold, and it is the recommended approach for objects over 100 MB because it also allows you to pause and resume uploads, reducing the impact of network interruptions.

Why this answer

Multipart upload improves throughput for large objects over 100 MB by uploading parts in parallel. Option C is correct because S3 Transfer Acceleration uses CloudFront edge locations to reduce latency for uploads over long distances. Option E is correct because using multiple S3 prefixes (i.e., parallelizing requests across different key prefixes) can increase the request rate and overall throughput.

Option B is incorrect because S3 Select is used to retrieve subsets of data from an object, not to upload. Option D is incorrect because transitioning to S3 Glacier is for data lifecycle management, not for improving upload performance.

55
MCQeasy

A developer notices that an EC2 instance running a web application is unreachable via its public IP. The instance passes status checks but security group rules appear correct. What should the developer check NEXT?

A.Verify that the instance has an Elastic IP associated.
B.Check the network ACL associated with the subnet for rules that may block traffic.
C.Review the route table for a route to an internet gateway.
D.Inspect the IAM role attached to the instance for network permissions.
AnswerB

Network ACLs are stateless, meaning both inbound and outbound rules must be explicitly evaluated for traffic to flow, unlike security groups which are stateful and automatically allow return traffic. In this scenario, the instance passes status checks and security group rules appear correct, so the developer must verify whether the subnet’s network ACL is blocking inbound or outbound traffic, satisfying the constraint that the issue lies at the subnet boundary rather than the instance or security group.

Why this answer

The instance passes status checks, the route table is confirmed to have a route to an internet gateway, and security group rules appear correct. Since the instance is still unreachable via its public IP, the next logical step is to check the network ACL (NACL) associated with the subnet. NACLs are stateless and can block inbound or outbound traffic even if security groups allow it.

NACLs evaluate rules in order by rule number, and a deny rule (or missing allow rule) for the required ephemeral ports (e.g., 1024-65535 for return traffic) could silently drop packets.

Exam trap

Candidates often assume security group rules are the only network filter and overlook the stateless nature of network ACLs, which can block traffic even when security groups and route tables are correctly configured.

How to eliminate wrong answers

Option A is wrong because an Elastic IP is not required for public IP reachability; an instance with a public IP assigned by AWS (from the subnet's auto-assign public IP setting) is reachable without an Elastic IP, so this check is premature and not the next step. Option C is wrong because the route table must have a route to an internet gateway for public traffic, but the question states the instance is unreachable via its public IP, and a missing route would typically cause a different symptom (e.g., no connectivity at all) rather than passing status checks; also, route tables are often checked earlier in troubleshooting, but the question specifies security groups appear correct, making NACL the more likely culprit. Option D is wrong because IAM roles control permissions for AWS API actions (e.g., S3, DynamoDB), not network-level traffic to/from the instance; network permissions are governed by security groups and NACLs, not IAM.

56
MCQeasy

Refer to the exhibit. A developer created this CloudFormation template. After deployment, the stack creation fails with 'Bucket name already exists'. What should the developer do to fix the issue?

A.Change the BucketName to include a random suffix.
B.Remove the MyQueue resource.
C.Remove the VersioningConfiguration from the bucket.
D.Set SqsManagedSseEnabled to false.
AnswerA

A hard-coded S3 BucketName such as MyBucket is not guaranteed to be globally unique; S3 bucket names are shared across all AWS accounts and regions, so the name may already be registered by another account. Changing the value to include a random suffix, for example by appending the AWS::AccountId or AWS::StackName pseudo parameter through Fn::Join or Fn::Sub, ensures a unique bucket name and allows the stack to create successfully.

Why this answer

The error 'Bucket name already exists' occurs because S3 bucket names are globally unique across all AWS accounts. The CloudFormation template hardcodes a BucketName that someone else already owns. The fix is to make the name unique, typically by appending a random suffix or using CloudFormation's auto-generated name (by omitting BucketName).

This ensures the stack can create a new bucket without collision.

Exam trap

DVA-C02 often tests the misconception that S3 bucket names are scoped to an account or region, when they are actually globally unique, leading candidates to overlook the need for a unique name.

How to eliminate wrong answers

Option B is wrong because removing the MyQueue resource does not address the S3 bucket name conflict and would break the application's messaging functionality. Option C is wrong because removing VersioningConfiguration does not resolve the global uniqueness requirement for bucket names. Option D is wrong because SqsManagedSseEnabled is a property of the SQS queue, not the S3 bucket, and toggling it has no effect on the bucket name collision.

57
MCQmedium

Why is the Lambda function not being invoked?

A.The Lambda execution role does not have permission to be invoked by S3.
B.The Lambda permission does not specify the correct source account.
C.The Lambda function has a runtime that is not supported.
D.The S3 bucket does not have a notification configuration for the Lambda function.
AnswerD

For an S3 bucket to trigger a Lambda function, a specific event notification configuration must be set up on the bucket. This configuration specifies which S3 events (e.g., s3:ObjectCreated:*) should trigger the Lambda function and identifies the target Lambda ARN. Without this explicit configuration, S3 will not publish events to the Lambda function, resulting in no invocation regardless of other permissions.

Why this answer

The most likely reason the Lambda function is not being invoked is that the S3 bucket does not have a notification configuration for the Lambda function. For S3 to invoke a Lambda function, you must configure an event notification on the bucket that specifies the Lambda function as the destination. Without this configuration, S3 will not send events to Lambda, and the function will never be invoked.

Exam trap

DVA-C02 often tests the difference between execution role permissions and resource-based policies. Candidates might think the execution role needs invoke permission, but actually S3 needs permission to invoke Lambda, which is granted via a resource-based policy, and the notification configuration must exist.

How to eliminate wrong answers

Option A is wrong because the Lambda execution role does not need permission to be invoked by S3; instead, S3 needs permission to invoke the Lambda function, which is granted via a resource-based policy on the Lambda function. Option B is wrong because while the Lambda permission must specify the correct source account, if it doesn't, S3 would receive an error when trying to invoke, but the function might still be invoked if the permission is correct; however, the question asks for the most likely reason for no invocation, and missing notification configuration is more fundamental. Option C is wrong because an unsupported runtime would cause the function to fail when invoked, not prevent invocation entirely.

58
MCQmedium

A developer is troubleshooting an AWS Lambda function that is triggered by an S3 event. The function occasionally fails with a timeout error. CloudWatch logs show that the timeout occurs during the processing of large files. The function has a memory setting of 128 MB and a timeout of 3 seconds. The developer wants to process large files without modifying the code. Which parameter should the developer adjust first?

A.Increase the function's memory
B.Increase the function's timeout
C.Increase the function's reserved concurrency
D.Increase the S3 event notification batch size
AnswerA

In AWS Lambda, memory allocation directly correlates with the amount of CPU power provisioned to the function. Increasing the function's memory provides more vCPUs, which can significantly speed up compute-intensive operations and data processing within the function's execution environment. This optimization can reduce the overall execution duration, thereby preventing timeouts and improving performance without requiring any changes to the underlying application code. It's often the first and most effective step for resolving performance bottlenecks.

Why this answer

Increasing the function's memory is the correct first step because Lambda allocates CPU proportionally to memory, and more CPU reduces processing time for CPU-bound tasks like decompressing or parsing large files. This directly addresses the timeout by making the function complete faster, without requiring code changes. The current 128 MB setting is the minimum, which provides the least CPU, so even a modest increase can significantly reduce execution time.

Exam trap

The trap here is that candidates often assume a timeout error must be fixed by increasing the timeout, but the question explicitly states the timeout occurs during processing of large files, indicating a performance bottleneck that memory (and thus CPU) increase can resolve without code changes.

How to eliminate wrong answers

Option B is wrong because increasing the timeout alone does not speed up processing; it only allows the function to run longer, which may mask the underlying performance issue but does not prevent future timeouts on even larger files. Option C is wrong because reserved concurrency controls the number of concurrent executions, not the execution duration of a single invocation; it would not resolve a timeout caused by slow processing. Option D is wrong because the S3 event notification batch size controls how many events are sent per invocation, not the processing speed of a single file; increasing it would only make the function handle more files per invocation, worsening the timeout.

59
MCQmedium

A developer needs to trace a request across API Gateway, Lambda, and downstream AWS service calls. Which service should be enabled?

A.AWS X-Ray
B.AWS Budgets
C.AWS Artifact
D.AWS License Manager
AnswerA

AWS X-Ray is the correct service for tracing requests across distributed applications, such as those involving API Gateway, Lambda functions, and other downstream AWS services. It provides an end-to-end view of requests as they travel through various components, helping identify performance bottlenecks and operational issues. X-Ray generates a service map that visualizes the application's architecture and shows latency data for each node and connection, enabling detailed analysis of request flow and performance. This capability is precisely what's needed to "trace a request" through the specified AWS services.

Why this answer

AWS X-Ray is the correct service because it provides end-to-end tracing for requests flowing through distributed applications, including API Gateway, Lambda functions, and downstream AWS services like DynamoDB or S3. It captures trace data as the request traverses each component, allowing developers to identify performance bottlenecks and errors across the entire request path. X-Ray integrates natively with API Gateway and Lambda via the X-Ray SDK or active tracing configuration, requiring no code changes for basic tracing.

Exam trap

The trap here is that candidates may confuse AWS X-Ray with CloudWatch Logs or CloudTrail, thinking those services provide the same distributed tracing capability, but X-Ray is the only service that correlates trace data across multiple components in a single request.

How to eliminate wrong answers

Option B (AWS Budgets) is wrong because it is a cost management service that monitors AWS spending and sends alerts when usage exceeds thresholds, not a tracing or observability tool. Option C (AWS Artifact) is wrong because it provides access to AWS compliance reports, security documentation, and agreements, such as SOC and PCI reports, not request tracing capabilities. Option D (AWS License Manager) is wrong because it manages software licenses (e.g., Microsoft, Oracle) to prevent license violations, and has no role in tracing API requests or debugging distributed applications.

60
MCQeasy

A developer is using AWS X-Ray to trace requests through a microservices application. One of the services, Service B, is not appearing in the trace map. What is the MOST likely reason?

A.Service B is using HTTP/2, which is not supported by X-Ray.
B.Service B is running in a different AWS region.
C.The X-Ray sampling rate is set too low.
D.Service B is not instrumented with the X-Ray SDK.
AnswerD

The X-Ray SDK is fundamental for any service to participate in distributed tracing. It's responsible for generating trace segments, capturing metadata, and propagating the trace context to downstream services. Without the X-Ray SDK integrated into Service B's code, the service cannot generate or send any trace data to the X-Ray daemon or service, thus preventing it from appearing on the service map.

Why this answer

For X-Ray to trace requests across services, each service must be instrumented with the X-Ray SDK. If Service B is not instrumented, it won't send trace data, and it won't appear in the trace map.

61
MCQmedium

A developer is optimizing a Node.js Lambda function that processes CSV files from S3. The function reads the entire file into memory, processes it, and writes results to DynamoDB. For large files, the function runs out of memory. What is the MOST effective optimization?

A.Increase the Lambda timeout to allow more processing time.
B.Increase the Lambda function memory to 3008 MB.
C.Use the AWS SDK's S3 GetObject with a stream and process in chunks.
D.Use S3 Select to retrieve only necessary columns.
AnswerC

Using the AWS SDK's S3 GetObject with a stream allows the Node.js Lambda function to read the large CSV file incrementally, rather than loading the entire object into memory at once. By processing data in small, manageable chunks as it arrives, the function significantly reduces its peak memory footprint. This approach directly addresses memory exhaustion by avoiding the need to hold the entire file in RAM, making it highly efficient for large file processing.

Why this answer

The core issue is that the Lambda function loads the entire CSV file into memory, causing out-of-memory errors for large files. Streaming the S3 object and processing it in chunks avoids holding the whole file in memory, keeping memory usage low and constant regardless of file size. This directly addresses the root cause—memory exhaustion—rather than just increasing resources or time limits.

It also allows the function to start processing immediately as data arrives, improving efficiency.

Exam trap

DVA-C02 often tests the misconception that increasing memory or timeout solves out-of-memory errors, when the real fix is to change the processing pattern to streaming or chunking.

How to eliminate wrong answers

Option A is wrong because increasing the timeout only allows the function to run longer; it does not reduce memory usage, so the function will still run out of memory before completing. Option B is wrong because increasing memory to 3008 MB (the maximum for Lambda) may delay the problem but does not solve it for arbitrarily large files; the function will still eventually exhaust memory if the file is large enough. Option D is wrong because S3 Select can reduce the amount of data retrieved by filtering columns or rows, but it still returns the entire result set at once, which could still be too large for memory; it does not provide streaming or chunked processing.

62
MCQmedium

A developer is deploying a new version of an AWS Lambda function using the AWS CLI. The deployment fails with a 'ResourceConflictException' error. What is the MOST likely cause?

A.Another deployment is currently in progress for the same Lambda function.
B.The Lambda function code exceeds the maximum allowed size.
C.The Lambda function has an alias that conflicts with the version number.
D.The IAM role associated with the Lambda function does not have sufficient permissions.
AnswerA

AWS Lambda enforces serialization of updates to a function's code or configuration to maintain consistency. If an API call like `UpdateFunctionCode` or `UpdateFunctionConfiguration` is initiated while another update operation is already in progress for the same function, the subsequent call will fail. This contention for the resource's state results in a `ResourceConflictException`, preventing race conditions and ensuring the function's configuration remains coherent.

Why this answer

The 'ResourceConflictException' error in AWS Lambda occurs when you attempt to update a Lambda function while another update operation is already in progress. Lambda enforces a single in-flight update per function to prevent race conditions and ensure state consistency. The AWS CLI command (e.g., update-function-code) will fail immediately if a previous deployment has not completed, even if the previous deployment was triggered by the same or a different client.

Exam trap

The trap here is that candidates confuse 'ResourceConflictException' with permission errors or code size limits, but AWS specifically uses this exception to signal a concurrent update conflict, not a validation or authorization issue.

How to eliminate wrong answers

Option B is wrong because exceeding the maximum code size (250 MB for zip, 50 MB for direct upload) results in a 'RequestEntityTooLargeException' or 'InvalidParameterValueException', not a 'ResourceConflictException'. Option C is wrong because alias names and version numbers are separate namespaces; an alias cannot conflict with a version number, and such a conflict would cause a 'ResourceNotFoundException' or 'InvalidParameterValueException' if you tried to reference a non-existent version. Option D is wrong because insufficient IAM permissions would result in an 'AccessDeniedException' or 'AuthorizationError', not a 'ResourceConflictException'.

63
MCQhard

A developer is using AWS Lambda with a VPC configuration. The function needs to access an Amazon RDS instance in the same VPC. The function is timing out after 3 seconds. What is the MOST likely cause?

A.The Lambda function's execution role does not have rds:Connect permission.
B.The Lambda function's security group does not allow outbound traffic to the RDS instance.
C.The Lambda function does not have an RDS proxy configured.
D.The Lambda function timeout is set too low.
AnswerB

When a Lambda function is configured within a VPC, its associated security groups govern both inbound and outbound network traffic. For the Lambda function to successfully establish a connection to an RDS instance, its security group must explicitly have an outbound rule permitting traffic to the RDS instance's private IP address or its security group, specifically on the database's listening port (e.g., 3306 for MySQL, 5432 for PostgreSQL). Without this crucial outbound rule, network packets cannot reach the database, resulting in connection failures.

Why this answer

The most likely cause of the Lambda function timing out when accessing an RDS instance in the same VPC is that the Lambda function's security group does not allow outbound traffic to the RDS instance's security group. Lambda functions in a VPC require security group rules that permit outbound traffic to the database, and inbound rules on the RDS security group to allow traffic from the Lambda function. Option A is incorrect because IAM permissions like rds:Connect are not used for network connectivity; they control API actions.

Option C is incorrect because an RDS proxy is not required for Lambda to connect to RDS; it's an optional feature for connection pooling. Option D is incorrect because although increasing the timeout might temporarily mask the issue, the root cause is a network connectivity problem, not the timeout value itself.

64
MCQmedium

A developer is troubleshooting an AWS Lambda function that writes to an S3 bucket. The function is configured with a resource-based policy that allows the S3 service to invoke the function. However, the function fails with an access denied error when trying to write to S3. What is the MOST likely cause?

A.The Lambda function is configured in a VPC without an S3 VPC endpoint.
B.The Lambda function's execution role does not have an IAM policy that allows s3:PutObject.
C.The Lambda function's trigger (S3 event notification) is misconfigured.
D.The S3 bucket policy does not grant the Lambda function write access.
AnswerB

The Lambda function's execution role is the IAM identity that the function assumes when it runs, dictating what AWS services and resources it is authorized to interact with. If this execution role lacks an IAM policy that explicitly grants the s3:PutObject permission, any attempt by the function to write or upload an object to an S3 bucket will be rejected by AWS Identity and Access Management (IAM). This directly leads to an "Access Denied" error, as the function is not authorized to perform that specific action.

Why this answer

The Lambda function's execution role lacks the necessary IAM permissions (s3:PutObject) to write to the S3 bucket. The resource-based policy only allows S3 to invoke the function, not the function to write. Option A is incorrect because a VPC endpoint would not cause an access denied error for writing if the execution role had permissions.

Option C is incorrect because trigger misconfiguration would prevent invocation, not cause access denied during execution. Option D is incorrect because the S3 bucket policy is not required if the execution role grants write access; the bucket policy controls who can access the bucket, but the execution role is the primary mechanism for Lambda permissions.

65
MCQmedium

A Lambda function processing SQS messages is failing with concurrency errors. The function is configured with reserved concurrency of 5. The SQS queue has a batch size of 10. What is the most effective way to prevent throttling?

A.Reduce the batch size to 1 to spread out invocations.
B.Increase the Lambda function memory to get more concurrency.
C.Increase the reserved concurrency to a higher value.
D.Set the SQS queue's concurrency limit to match the Lambda reserved concurrency.
AnswerC

Increasing the reserved concurrency for the Lambda function dedicates a specific number of concurrent execution slots exclusively to that function. This guarantees that the function will always have that many concurrent instances available, preventing it from being throttled by the overall account-level concurrency limit or by other functions consuming available capacity. By reserving more concurrency, the function can process a higher parallel load from SQS without interruption, directly addressing throttling issues.

Why this answer

The function is throttling due to insufficient reserved concurrency. With a batch size of 10, each SQS batch triggers one invocation, but the function's reserved concurrency of 5 limits concurrent executions to 5. Increasing reserved concurrency allows more concurrent invocations to handle the SQS messages without throttling.

Exam trap

The trap here is that candidates often confuse batch size with concurrency, thinking reducing batch size reduces load, but it actually increases invocation count and worsens throttling.

How to eliminate wrong answers

Option A is wrong because reducing the batch size to 1 would increase the number of invocations per message, worsening concurrency pressure and potentially increasing throttling. Option B is wrong because increasing Lambda memory does not affect concurrency limits; memory and concurrency are independent settings. Option D is wrong because SQS queues do not have a configurable concurrency limit; Lambda's event source mapping manages polling, and setting a non-existent queue concurrency limit is not a valid action.

66
MCQmedium

The developer invokes a Lambda function using the AWS CLI and gets the output shown. What is the most likely cause of the error?

A.The Lambda function code has a syntax error.
B.The Lambda function's execution role lacks permissions.
C.The event payload does not contain the expected data.
D.The Lambda function timed out.
AnswerC

When a Lambda function's code attempts to access a property or key within the `event` object that does not exist in the incoming JSON payload, it will result in a `TypeError`. For instance, if the code expects `event.detail.itemId` but the payload only contains `{"id": "123"}`, accessing `event.detail` would return `undefined`. Subsequently, attempting to access `itemId` on `undefined` would raise a `TypeError` because `undefined` has no properties, indicating a mismatch between expected and actual data structure.

Why this answer

When a Lambda function is invoked with a payload that does not match the handler's expected schema, the function raises a runtime error such as KeyError or TypeError, which surfaces as a function error in the CLI output. The most likely cause is a malformed or unexpected event payload rather than an infrastructure issue.

Exam trap

DVA-C02 often tests the distinction between a function-level error (bad payload, unhandled exception) and a service-level error (permissions, timeout) — candidates misread the CLI output and blame IAM when the payload is the real culprit.

How to eliminate wrong answers

Option A is wrong because a syntax error would prevent deployment entirely — Lambda validates code at upload, so the function would not be invocable. Option B is wrong because missing execution role permissions typically produce an AccessDeniedException from an AWS API call inside the function, not a generic handler error on the payload. Option D is wrong because a timeout produces a Task timed out after X seconds message and a 200 response with a timeout error, not a payload-related error.

67
MCQeasy

A developer is using Amazon DynamoDB with provisioned throughput. The application is receiving ProvisionedThroughputExceededException errors. What is the BEST way to handle this error?

A.Contact AWS Support to increase the DynamoDB service limits.
B.Reduce the read and write capacity units.
C.Implement exponential backoff and retry in the application code.
D.Switch the table to on-demand capacity mode.
AnswerC

Implementing exponential backoff and retry logic in the application code is a standard best practice for gracefully handling transient errors like `ProvisionedThroughputExceededException` in DynamoDB. This mechanism automatically retries failed requests after progressively longer delays, allowing the throttled table time to recover or for its burst capacity to replenish. It prevents a flood of immediate retries from overwhelming the table further, enabling the application to adapt to temporary capacity limitations.

Why this answer

The ProvisionedThroughputExceededException indicates that the application has exceeded the provisioned read/write capacity units for the DynamoDB table. The best practice to handle this error is to implement exponential backoff and retry logic in the application code, which progressively increases the wait time between retries to reduce request volume and allow the throttling to subside. This approach is recommended by AWS for handling throttling errors gracefully without manual intervention.

Exam trap

The trap here is that candidates often confuse 'handling the error' with 'preventing the error' and choose to switch to on-demand mode (Option D) instead of implementing proper retry logic, which is the immediate and correct response to a throttling exception.

How to eliminate wrong answers

Option A is wrong because contacting AWS Support to increase DynamoDB service limits does not address the root cause of exceeding provisioned throughput; service limits are separate from provisioned capacity and increasing them does not resolve throttling. Option B is wrong because reducing read and write capacity units would decrease the table's throughput, making throttling more likely, not less. Option D is wrong because switching to on-demand capacity mode is a valid long-term solution for unpredictable workloads but is not the best immediate fix for handling the exception in existing code; it also incurs higher costs and does not teach the application to handle throttling programmatically.

68
MCQeasy

A developer deploys a new version of an AWS Lambda function using the AWS CLI. After deployment, the function returns stale results. What is the most likely cause?

A.The function's environment variables are cached and not updated.
B.The Lambda function alias is still pointing to the previous version.
C.The Amazon CloudFront distribution is caching the old response.
D.The Lambda function's code is cached by the Lambda service.
AnswerB

Lambda aliases provide a stable endpoint for invoking a function, but they are explicitly configured to point to a specific function version. If a developer deploys a new version of the Lambda function but fails to update the associated alias to reference this new version, any invocations made through that alias will continue to execute the code and configuration of the older version it still references. This is a common operational oversight leading to unexpected behavior where new code doesn't appear to be running.

Why this answer

When a developer deploys a new version of a Lambda function using the AWS CLI without updating the function alias, the alias continues to point to the previous version. Invoking the function via the alias (e.g., via an API Gateway endpoint or a CloudFront origin) will execute the old code, returning stale results. The `$LATEST` version is updated, but unless the alias is repointed, it does not automatically use the new code.

Exam trap

The trap here is that candidates may assume deploying new code automatically updates the invoked version, overlooking that aliases must be explicitly repointed to the new version to change which code is executed.

How to eliminate wrong answers

Option A is wrong because environment variables are not cached; they are read from the function's configuration at invocation time and are updated immediately when the function is deployed with new environment variables. Option C is wrong because CloudFront caching is a separate concern; while it can serve stale responses, the question states the function itself returns stale results, and CloudFront would only cache the HTTP response, not the Lambda execution output directly. Option D is wrong because the Lambda service does not cache the function's code in a way that persists across deployments; the new code is immediately available when the function version is updated, and the issue is about which version is being invoked, not code caching.

69
MCQhard

A company runs a microservices application on Amazon ECS with Fargate. The application includes a service that processes messages from an SQS queue. The service's CPU utilization is consistently above 80%, and messages are accumulating in the queue. The service is configured with a desired count of 2 tasks and auto scaling based on CPU utilization. What should a developer do to improve message processing throughput?

A.Increase the desired count of tasks to 5.
B.Increase the task size to use more CPU and memory.
C.Change the auto scaling metric to use the SQS queue's ApproximateNumberOfMessagesVisible.
D.Decrease the batch size of messages polled from SQS.
AnswerC

Switching the target tracking metric to ApproximateNumberOfMessagesVisible makes scaling decisions proportional to the actual backlog size rather than an indirect CPU proxy, so the service adds tasks precisely when the queue grows and removes them as it drains, directly improving throughput.

Why this answer

The correct answer because using the SQS queue's ApproximateNumberOfMessagesVisible metric for auto scaling is more responsive to the actual workload than CPU utilization. When messages accumulate in the queue, scaling based on queue depth triggers task additions sooner, improving throughput. Option A is wrong because simply increasing the desired count without a dynamic scaling policy may not adapt to varying load and could lead to over-provisioning or under-provisioning.

Option B is wrong because increasing task size (CPU/memory) does not directly address the scaling trigger; it might help a single task process more, but the bottleneck is the number of tasks. Option D is wrong because decreasing the batch size reduces the number of messages processed per poll, which would decrease throughput, not improve it.

70
MCQmedium

A developer is debugging an issue where an Amazon S3 bucket policy is not allowing cross-account access for a user from another AWS account. The bucket policy grants access to the other account's root user. The IAM user in the other account has an IAM policy that allows s3:GetObject on the bucket. When the user tries to download an object, they get an Access Denied error. What is the most likely cause?

A.The bucket is encrypted with SSE-KMS and the user does not have kms:Decrypt permission
B.The bucket policy does not specify the user's ARN
C.The object's ACL is set to private
D.The IAM policy does not include s3:ListBucket
AnswerA

When an S3 object is encrypted with Server-Side Encryption using AWS Key Management Service (SSE-KMS), the requesting principal requires two distinct permissions for GetObject operations. Beyond the s3:GetObject permission on the bucket, an explicit kms:Decrypt permission on the specific AWS KMS key used for encryption is mandatory. Without this crucial KMS permission, even a valid S3 bucket policy allowing s3:GetObject will result in an Access Denied error, as S3 cannot decrypt the object for the user.

Why this answer

The most likely cause is that the bucket is encrypted with SSE-KMS. When an S3 bucket uses AWS KMS customer master keys (CMKs) for server-side encryption, the bucket policy granting access to the root user of the other account is not sufficient. The IAM user in the other account must also have explicit kms:Decrypt permission on the KMS key, because S3 GetObject calls require decrypting the object before returning it.

Without this KMS permission, the request fails with Access Denied even though the S3 bucket policy and IAM policy appear correct.

Exam trap

The trap here is that candidates assume a valid S3 bucket policy and IAM policy are sufficient, forgetting that KMS encryption adds an independent authorization layer that requires explicit kms:Decrypt permissions, which is a common oversight in cross-account S3 access scenarios.

How to eliminate wrong answers

Option B is wrong because the bucket policy grants access to the other account's root user, which covers all IAM users and roles in that account by default; specifying the individual user's ARN is not required. Option C is wrong because object ACLs are evaluated after bucket policies, and if the bucket policy explicitly grants access, a private object ACL would be overridden (unless the bucket policy has a condition denying access). Option D is wrong because s3:ListBucket is only needed for listing objects (e.g., GET Bucket (List Objects) requests), not for downloading a specific object using s3:GetObject.

71
Matchingmedium

Match each AWS storage class to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Frequent access, low latency

Automatic cost optimization

Long-term archival

Infrequent access, single AZ

Lowest cost retrieval

Why these pairings

The correct matches are S3 Standard with frequently accessed data, S3 Intelligent-Tiering with automatic cost optimization, S3 Glacier Instant Retrieval with archive and fast retrieval, and S3 One Zone-IA with infrequent data in one AZ. Common confusions include mixing up storage class descriptions.

72
MCQhard

An application uses an Auto Scaling group with a launch configuration that includes a user data script to configure instances. After a scaling event, new instances launch but fail to register with the target group. The existing instances continue to work. What should the developer do to resolve this issue?

A.Modify the existing launch configuration with the correct user data
B.Create a new launch configuration with corrected user data and update the Auto Scaling group
C.Update the Auto Scaling group to use the latest launch configuration version
D.Delete and recreate the Auto Scaling group
AnswerB

This is the correct and standard procedure for updating instance launch parameters for an Auto Scaling group. First, a new launch configuration must be created, incorporating the corrected user data. Subsequently, the Auto Scaling group is updated to reference this newly created launch configuration. New instances launched by the Auto Scaling group will then utilize the updated user data, while existing instances remain unaffected until they are terminated and replaced.

Why this answer

Launch configurations are immutable — once created, they cannot be modified. To fix incorrect user data, the developer must create a new launch configuration with the corrected script and update the Auto Scaling group to reference it. Existing instances keep running with the old configuration, but new instances launched after the update will use the corrected user data and register successfully.

Exam trap

DVA-C02 often tests the immutability of launch configurations — candidates incorrectly assume they can be edited like launch template versions, or confuse the two services entirely.

How to eliminate wrong answers

Option A is wrong because launch configurations cannot be edited after creation; AWS explicitly makes them immutable to preserve versioning integrity. Option C is wrong because launch configurations don't have versions (unlike launch templates) — this option confuses launch configurations with launch templates, which do support versioning. Option D is wrong because deleting and recreating the Auto Scaling group is unnecessary and disruptive; updating the group's launch configuration reference is sufficient.

73
MCQeasy

A developer is troubleshooting a slow-running query in Amazon RDS for MySQL. The query is used by a reporting dashboard. Which AWS service should the developer use to identify the bottleneck?

A.AWS X-Ray
B.AWS CloudTrail
C.Amazon RDS Performance Insights
D.Amazon CloudWatch Logs
AnswerC

Amazon RDS Performance Insights is a purpose-built monitoring tool that provides a visual dashboard to analyze database performance by focusing on active sessions and wait events. It aggregates and displays key metrics, allowing developers to quickly identify the top SQL queries, users, hosts, or wait types that are consuming database resources. This granular, real-time insight is specifically designed for troubleshooting and optimizing slow-running queries within Amazon RDS databases.

Why this answer

Amazon RDS Performance Insights provides a detailed analysis of database performance, including wait events and SQL query performance, helping identify bottlenecks.

74
MCQhard

A developer is troubleshooting an AWS Lambda function that is invoked from an Amazon S3 bucket via event notifications. The function processes images and stores metadata in Amazon DynamoDB. The developer notices that some images are being processed multiple times, resulting in duplicate entries in DynamoDB. The S3 event notification is configured to send events to the Lambda function with the 's3:ObjectCreated:*' event type. The function uses the 'uuid' library to generate a unique ID for each image upon processing. What is the most likely cause of the duplicate processing?

A.S3 event notifications are delivered at least once, and the Lambda function is not idempotent.
B.The Lambda function's concurrency is set too high, causing race conditions.
C.The DynamoDB table does not have a primary key that prevents duplicates.
D.The S3 bucket is configured with versioning, causing multiple object creation events.
AnswerA

S3 event notifications operate on an "at least once" delivery model, meaning that a single S3 event, such as an object creation, might trigger the associated Lambda function multiple times. If the Lambda function's logic is not designed to be idempotent, each duplicate invocation will independently process the event and perform its side effects, leading to duplicate data entries or actions. Implementing idempotency, often by using a unique identifier from the S3 event (like the object key) as a check, is crucial to prevent these redundant operations.

Why this answer

Amazon S3 event notifications are delivered on an 'at least once' basis, meaning the same event can be sent to Lambda multiple times. If the Lambda function is not idempotent—i.e., processing the same event multiple times produces duplicate side effects—then duplicate DynamoDB entries will occur. The use of a 'uuid' library inside the function does not help because a new UUID is generated on each invocation, so the same image gets different IDs and is stored as a separate item each time.

Exam trap

The trap here is that candidates assume generating a unique ID inside the function solves duplication, but they miss that idempotency requires using a stable, external identifier (like the S3 object key) to detect and skip already-processed events.

How to eliminate wrong answers

Option B is wrong because high concurrency can cause race conditions, but the core issue here is duplicate event delivery, not concurrent writes; even with low concurrency, duplicate events would still be processed. Option C is wrong because the DynamoDB table's primary key design does not cause duplicate processing; it only affects whether duplicate writes are rejected or overwritten—the problem is that the function is invoked multiple times for the same image. Option D is wrong because S3 versioning generates separate object versions, each with a unique version ID, and the 's3:ObjectCreated:*' event fires once per version; versioning does not cause multiple events for the same object version.

75
MCQeasy

The exhibit shows a CloudFormation template that creates an S3 bucket with versioning enabled. After deploying the stack, a developer uploads an object to the bucket. Later, the developer updates the object by uploading a new version. The developer wants to retrieve the original object. What is the correct way to do this?

A.Restore the original object using the S3 Object Lambda.
B.Use the S3 Batch Operations to revert to the original version.
C.The original object is overwritten and cannot be retrieved.
D.Use the S3 console or CLI to list object versions and retrieve the version ID of the original object.
AnswerD

S3 Versioning automatically retains every version of an object whenever it is modified or deleted, assigning each a unique version ID. To retrieve the original object, one must first identify its specific version ID among the stored versions. Both the AWS Management Console and the AWS Command Line Interface (CLI) offer functionalities to list all object versions, enabling precise retrieval of the desired historical state.

Why this answer

With S3 versioning enabled, uploading a new version of an object does not overwrite the original — it creates a new version and retains the previous one. The developer can retrieve the original by listing object versions (via console or aws s3api list-object-versions) to find the original version ID, then downloading that specific version.

Exam trap

DVA-C02 often tests the misconception that uploading a new object overwrites the old one — candidates must remember that versioning retains prior versions retrievable by version ID.

How to eliminate wrong answers

Option A is wrong because S3 Object Lambda transforms data during retrieval (e.g., redaction, format conversion); it does not restore or retrieve prior versions. Option B is wrong because S3 Batch Operations performs bulk actions on existing objects (copy, tag, invoke Lambda) and is not a version-reversion mechanism. Option C is wrong because versioning explicitly prevents overwriting — the original version remains retrievable, so this statement is factually incorrect.

Page 1 of 3 · 179 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Troubleshooting and Optimization questions.