Courseiva

CCNA Troubleshooting and Optimization Questions

29 of 179 questions · Page 3/3 · Troubleshooting and Optimization · Answers revealed

151
MCQhard

Refer to the exhibit. An IAM policy is attached to a user. The user tries to download an object from s3://my-bucket/secret/config.txt. What will happen?

A.The user is denied access only if the bucket policy also denies access.
B.The user can download the object because the Deny statement only applies to 's3:*' actions, not s3:GetObject.
C.The user can download the object because the Allow statement grants s3:GetObject on the bucket.
D.The user is denied access because the Deny statement explicitly denies access to the 'secret/' prefix.
AnswerD

The policy's Deny statement denies all s3 actions on the ARN arn:aws:s3:::bucket/secret/*, which matches the requested object in the 'secret/' prefix. An explicit deny always overrides any allow, including the separate Allow statement granting s3:GetObject on the bucket. Therefore, the user is denied access to that object, and this is the correct interpretation of the policy evaluation outcome.

Why this answer

The Deny statement explicitly denies all s3 actions on the 'secret/' prefix. Deny statements override Allow statements. Therefore, the user is denied access to objects under the 'secret/' prefix, including s3://my-bucket/secret/config.txt.

Option D is correct. Option A is incorrect because the explicit Deny overrides any bucket policy allow. Option B is incorrect because the Deny applies to all s3 actions, including s3:GetObject, and is scoped to the 'secret/' prefix.

Option C is incorrect because the Allow statement does not grant access to the 'secret/' prefix; the Deny overrides it.

152
Multi-Selectmedium

Which TWO actions can help reduce latency for a web application hosted on EC2 instances behind an Application Load Balancer? (Select TWO.)

Select 2 answers
A.Increase the EC2 instance size to a larger type.
B.Use Amazon CloudFront as a content delivery network.
C.Disable keep-alive connections on the ALB.
D.Use multiple Availability Zones for the ALB.
E.Enable HTTP/2 on the Application Load Balancer.
AnswersB, E

Amazon CloudFront, a global content delivery network (CDN), significantly reduces latency by caching static and dynamic content at edge locations worldwide. When a user requests content, CloudFront serves it from the nearest edge location, minimizing the physical distance data must travel. This reduces the round-trip time (RTT) between the user and the content source, resulting in faster load times and an improved user experience compared to fetching all content directly from the origin server in a single AWS region.

Why this answer

Option B is correct because Amazon CloudFront caches content at edge locations closer to end users, reducing round-trip time and offloading requests from the ALB and EC2 origin, which directly lowers latency for the web application. Option E is correct because ALBs natively support HTTP/2, and enabling it allows multiplexed streams over a single TCP connection, reducing connection overhead and improving page load latency for clients. Option A is not necessarily correct because a larger instance type increases compute capacity but does not inherently reduce network latency.

Option C is incorrect because disabling keep-alive forces new TCP/TLS handshakes per request, increasing latency. Option D is incorrect because using multiple Availability Zones improves availability and fault tolerance, not latency.

Exam trap

DVA-C02 often tests the misconception that adding AZs or scaling instance size reduces latency, when those address availability and capacity, not network round-trip time.

153
MCQmedium

A developer has deployed a serverless application using AWS SAM. After a recent update, the API Gateway endpoints return 500 errors. The Lambda function logs show no errors. What should the developer investigate first?

A.Increase the Lambda function timeout.
B.Check the Lambda function's reserved concurrency.
C.Review the CloudFormation stack events for any failures.
D.Verify the API Gateway integration response and mapping templates.
AnswerD

Even if a Lambda function executes successfully and returns a valid response, API Gateway can still return a 500 Internal Server Error to the client if its integration response or mapping templates are misconfigured. These templates are responsible for transforming the Lambda function's output into the final HTTP response format expected by the client. A failure in this transformation process within API Gateway itself often manifests as a 500 error.

Why this answer

When API Gateway returns 500 errors but Lambda logs show no errors, the issue is typically in the API Gateway integration response or mapping templates. API Gateway may fail to transform the Lambda response into the expected format, causing an internal server error without the Lambda function ever throwing an exception.

Exam trap

The trap here is that candidates assume 500 errors always originate from the Lambda function, but the question explicitly states Lambda logs show no errors, forcing the candidate to look at the API Gateway integration layer instead.

How to eliminate wrong answers

Option A is wrong because increasing the Lambda function timeout would not resolve 500 errors if the function is completing successfully (as indicated by no errors in logs); timeout issues would manifest as 504 errors, not 500. Option B is wrong because reserved concurrency controls the number of concurrent executions, not response formatting; concurrency issues would cause throttling (429 errors) or invocation failures, not 500 errors with successful logs. Option C is wrong because CloudFormation stack events would show deployment failures, but the question states the application was deployed successfully and only after an update the errors appeared; stack events would not reveal runtime integration issues between API Gateway and Lambda.

154
MCQmedium

A developer is troubleshooting an application that uses Amazon ElastiCache for Redis to cache database query results. The application experiences high latency during cache misses. The developer notices that frequently accessed keys (hot keys) are often missing from the cache, suggesting they are being evicted. Which action should the developer take to reduce cache misses for hot keys?

A.Increase the number of cache nodes.
B.Switch to the 'allkeys-lru' eviction policy.
C.Disable the TTL on all cached keys.
D.Increase the size of the cache cluster.
AnswerB

allkeys-lru evicts the least recently used keys from all keys, which tends to retain frequently used hot keys.

Why this answer

ElastiCache for Redis defaults to the 'volatile-lru' eviction policy, which considers only keys that have a TTL for eviction. Under memory pressure, Redis may evict frequently accessed TTL-bearing keys while cold keys without TTL cannot be evicted. Switching to 'allkeys-lru' expands the candidate set to include keys without TTL, allowing Redis to evict less-recently-used non-TTL keys first and reducing the likelihood that hot TTL-bearing keys are evicted.

Exam trap

The trap here is that candidates assume scaling up or out is the only solution for cache misses, overlooking that the eviction policy directly controls which keys are removed under memory pressure, and 'volatile-lru' by default excludes keys without TTL from eviction consideration.

How to eliminate wrong answers

Option A is wrong because increasing the number of cache nodes (scaling out) distributes data across shards but does not change the eviction policy; hot keys can still be evicted under memory pressure if the policy does not protect them. Option C is wrong because disabling TTL on all cached keys would prevent expiration-based eviction but does not address eviction due to memory limits; Redis would still evict keys under the 'volatile-lru' policy, and without TTL, those keys become ineligible for eviction, potentially causing out-of-memory errors. Option D is wrong because increasing the size of the cache cluster (scaling up) adds more memory, which delays eviction but does not change the eviction policy; hot keys without TTL remain vulnerable to eviction once memory is exhausted.

155
MCQhard

A developer is troubleshooting an AWS Lambda function that processes large CSV files (up to 1 GB) uploaded to an Amazon S3 bucket. The function uses Python and the pandas library to perform data transformations. Recently, the function started timing out on large files. CloudWatch Logs show that the function's execution time is close to the 15-minute Lambda timeout, and memory utilization peaks at around 80% of the configured 3,008 MB. The function has not been modified in months. Which action will most likely resolve the timeout issue without requiring code changes?

A.Increase the memory allocation of the Lambda function to the maximum available (10,240 MB)
B.Increase the function timeout to the maximum allowed (900 seconds is already the max)
C.Use S3 Select to filter columns and rows before invoking the Lambda function
D.Increase the batch size of the S3 event notification to invoke the function with multiple files
AnswerA

Increasing the Lambda function's memory allocation directly scales the available CPU power, network bandwidth, and ephemeral storage. For CPU-intensive tasks like `pandas` processing of large CSV files, more CPU can significantly accelerate computations, reducing the overall execution time. This approach is highly effective in preventing timeouts by providing the necessary resources to complete the workload within the allowed duration, without requiring any changes to the existing function code.

Why this answer

Increasing the memory allocation to the maximum (10,240 MB) proportionally increases the CPU and network throughput allocated to the Lambda function, which directly reduces execution time for CPU-bound pandas operations. Since memory utilization is only at 80% of the current 3,008 MB, the bottleneck is likely CPU, not memory, and Lambda's CPU scales linearly with memory configuration. This action resolves the timeout without any code changes.

Exam trap

The trap here is that candidates assume the function needs more memory because memory utilization is at 80%, but the real bottleneck is CPU, which is tied to memory allocation in Lambda's pricing and performance model.

How to eliminate wrong answers

Option B is wrong because the Lambda function timeout is already at 900 seconds (15 minutes), which is the maximum allowed; increasing it further is impossible. Option C is wrong because S3 Select filters data before the Lambda function is invoked, which would require modifying the S3 event notification or adding a separate trigger, thus requiring code changes to the Lambda function or infrastructure. Option D is wrong because increasing the batch size of the S3 event notification would invoke the function with multiple files at once, which would increase the processing load and worsen the timeout issue, not resolve it.

156
Multi-Selectmedium

A developer is troubleshooting a slow-performing Amazon RDS for MySQL database. Which TWO actions should the developer take to improve query performance?

Select 2 answers
A.Delete unused indexes to reduce write overhead.
B.Enable Multi-AZ deployment for better read performance.
C.Increase the instance size to provide more CPU and memory.
D.Enable the slow query log to identify poorly performing queries.
E.Delete the binary log files to free up storage.
AnswersC, D

Scaling up to a larger instance class directly addresses the symptoms by giving the database engine more vCPUs and more memory. With additional memory, the InnoDB buffer pool can cache more data and index pages, reducing disk I/O, while extra CPU accelerates query execution, sorting, and joins. This is an appropriate immediate mitigation when CloudWatch metrics show high CPU utilization or high swap usage, though it doesn't fix inefficient queries.

Why this answer

Option C is correct because a slow-performing RDS for MySQL instance is often constrained by CPU, memory, or IOPS, and vertically scaling to a larger instance class provides more vCPU, RAM, and baseline EBS throughput, which directly improves query execution and buffer pool caching. Option D is correct because enabling the MySQL slow query log (via the slow_query_log and long_query_time parameters in a custom parameter group) captures queries exceeding the threshold, letting the developer identify and then optimize the specific poorly performing SQL statements. Option A is not appropriate because deleting indexes generally hurts read performance and only marginally reduces write overhead, and unused indexes are not the typical cause of slow queries.

Option B is wrong because Multi-AZ is a high-availability/failover feature that maintains a synchronous standby, not a read-scaling mechanism, so it does not improve read performance. Option E is wrong because purging binary logs only frees storage and does not address query performance, and it can break point-in-time recovery and replication.

Exam trap

The trap here is conflating Multi-AZ with read scaling — candidates pick Multi-AZ thinking the standby serves reads, when only Read Replicas do that.

157
MCQmedium

A developer is troubleshooting a CloudFormation stack that fails to create. The stack includes an Auto Scaling group with a launch template. The error message says 'Value (null) for parameter groupId is invalid.' What is the MOST likely cause?

A.The launch template references a SecurityGroupId parameter that is not provided or is misspelled.
B.The Auto Scaling group does not specify a VPC subnet.
C.The Auto Scaling group's user data script contains a syntax error.
D.The launch template specifies an invalid key pair name.
AnswerA

When a CloudFormation launch template attempts to create an EC2 instance, it requires valid security group IDs. If the template references a `SecurityGroupId` parameter that is either not declared in the CloudFormation template's `Parameters` section, or if the `Ref` function used to access it contains a typo, CloudFormation will fail to resolve a concrete value. This results in a null or empty value being passed to the EC2 API for `groupId`, leading to a validation error during stack creation.

Why this answer

The error 'Value (null) for parameter groupId is invalid' indicates that a SecurityGroupId parameter referenced in the launch template is either not provided or misspelled. CloudFormation resolves parameters at stack creation; if the parameter is missing or has a typo, it evaluates to null, causing the launch template to fail validation because a security group ID is required for the network interface.

Exam trap

The trap here is that candidates confuse a missing subnet or user data error with a parameter null value, but the specific 'groupId' error points directly to a security group parameter issue, not infrastructure or script problems.

How to eliminate wrong answers

Option B is wrong because a missing VPC subnet would cause a different error, such as 'VPCIdNotSpecified' or 'SubnetIDNotSpecified', not a null groupId parameter. Option C is wrong because a syntax error in user data would result in a script execution failure, not a parameter validation error during stack creation. Option D is wrong because an invalid key pair name would produce an error like 'InvalidKeyPair.NotFound', not a null parameter value for groupId.

158
MCQmedium

The exhibit shows the output of invoking a Lambda function from the AWS CLI. The function returned a status code of 200 but included a FunctionError field set to 'Unhandled'. What does this indicate?

A.The function executed but threw an unhandled exception.
B.The function returned an error in the LogResult field.
C.The function timed out during execution.
D.The function was invoked but there was a network error.
AnswerA

A 200 status code confirms the invocation reached the function and returned a response, while FunctionError set to 'Unhandled' signals the runtime caught an exception the code did not handle. The function executed but terminated abnormally, so the handler threw an unhandled error.

Why this answer

When a Lambda function returns a status code of 200 but includes a FunctionError field set to 'Unhandled', it means the function was invoked successfully but encountered an unhandled exception during execution. The 'Unhandled' error indicates that the function threw an error that was not caught by the function's code, causing the Lambda runtime to report it. The status code 200 refers to the HTTP response from the Lambda service, not the function's execution status.

Exam trap

DVA-C02 often tests the confusion between HTTP status codes and function execution errors, leading candidates to think a 200 status means success even when FunctionError is present.

How to eliminate wrong answers

Option B is wrong because the LogResult field contains base64-encoded logs, not error information; the FunctionError field specifically indicates an unhandled exception. Option C is wrong because a timeout would result in a FunctionError of 'Unhandled' with a specific timeout message, but the question states the function returned a status code 200, which would not happen on timeout. Option D is wrong because a network error would typically result in a different error, such as a connection error, not a FunctionError field in the response.

159
Multi-Selectmedium

A developer is using AWS Elastic Beanstalk to deploy a web application. The application is experiencing high latency. Which TWO steps should the developer take to troubleshoot and optimize the application?

Select 2 answers
A.Configure an Amazon RDS read replica.
B.Enable AWS X-Ray integration and analyze service maps.
C.Enable enhanced health reporting and review the environment health metrics.
D.Increase the instance type to a larger size.
E.Deploy the application to a different AWS region.
AnswersB, C

Enabling AWS X-Ray on Elastic Beanstalk instruments your application and produces service maps and traces that reveal end-to-end request paths, downstream call latencies, and dependency errors. Analyzing these maps pinpoints slow segments such as API calls, database queries, or third-party services that contribute to user-facing latency. This is precisely the diagnostic step needed to focus on the actual bottleneck in the code or call chain.

Why this answer

AWS X-Ray integration provides tracing to identify bottlenecks in the application. Option C is correct because enhanced health reporting gives detailed environment health metrics for troubleshooting. Option A is wrong because an RDS read replica is for database read scaling, not directly for latency troubleshooting.

Option D is wrong because increasing the instance type is a scaling solution, not a troubleshooting step. Option E is wrong because deploying to a different region does not address latency for existing users.

160
MCQmedium

A developer is troubleshooting an AWS Lambda function that processes records from an Amazon Kinesis Data Stream. The function is configured with a batch size of 100 and a parallelization factor of 1. The iterator age metric is increasing, and CloudWatch Logs show the function execution time is around 4 minutes (timeout is 5 minutes). The stream has 10 shards. What is the most cost-effective way to increase processing throughput?

A.Increase the batch size to 500
B.Increase the number of shards
C.Increase the timeout to 10 minutes
D.Increase the parallelization factor per shard
AnswerD

Increasing the parallelization factor per shard for a Kinesis stream event source mapping allows a single Lambda function to process multiple concurrent batches from the *same* shard. By default, Lambda processes one batch per shard concurrently. Raising this factor (up to 10) directly boosts the effective processing throughput from each shard without incurring additional Kinesis shard costs, making it a highly efficient way to reduce iterator age and catch up on backlog.

Why this answer

Increasing the parallelization factor per shard (option D) allows each shard to be processed by multiple Lambda instances concurrently, which directly increases throughput without requiring additional shards or changes to the stream. Since the function is not hitting the 5-minute timeout but is taking ~4 minutes per batch, the bottleneck is processing concurrency per shard, not batch size or execution duration. This is the most cost-effective solution because it uses existing shards and avoids the cost of additional shards or unnecessary timeout increases.

Exam trap

The trap here is that candidates often assume increasing batch size (option A) is the natural fix for slow processing, but they overlook that the function is already near its timeout limit, making a larger batch size impractical without also increasing the timeout.

How to eliminate wrong answers

Option A is wrong because increasing the batch size to 500 would likely cause the function to exceed the 5-minute timeout (since it already takes ~4 minutes for 100 records), leading to throttling and failed processing. Option B is wrong because increasing the number of shards incurs additional costs and is not the most cost-effective approach; the current 10 shards are underutilized due to the parallelization factor of 1. Option C is wrong because the function is not timing out (it completes in ~4 minutes with a 5-minute timeout), so increasing the timeout does not address the throughput bottleneck and only delays potential failures.

161
Multi-Selectmedium

A developer is troubleshooting an AWS Lambda function that is timing out. The function has a timeout of 5 seconds and is configured with 128 MB of memory. Which TWO of the following are effective ways to resolve the timeout?

Select 2 answers
A.Increase the memory allocation to 512 MB.
B.Decrease the memory allocation to 64 MB.
C.Deploy the function inside a VPC.
D.Optimize the function code to reduce execution time.
E.Increase the function timeout to 10 seconds.
AnswersA, D

Increasing the memory allocation for an AWS Lambda function directly scales the available CPU power proportionally. This provides more computational resources, allowing the function to process data faster and complete tasks in less time. Additionally, higher memory allocations often come with increased network bandwidth, which can significantly reduce I/O bound delays for functions interacting with other AWS services or external APIs, thereby mitigating potential timeouts.

Why this answer

Increasing memory allocation in AWS Lambda proportionally increases CPU and network throughput, which can reduce execution time and prevent timeouts. With 128 MB, the function may be CPU-bound; raising it to 512 MB provides more compute resources, often resolving timeout issues without code changes.

Exam trap

The trap here is that candidates often think increasing the timeout alone is a valid fix, but the DVA-C02 exam emphasizes resolving the root cause (e.g., insufficient resources or inefficient code) rather than just extending the timeout window.

162
MCQhard

A developer is running an AWS Lambda function that is triggered by Amazon S3 events. The function writes processed data to an Amazon DynamoDB table. Over time, the function's execution time has increased significantly. CloudWatch Logs show many DynamoDBProvisionedThroughputExceededException errors. The table is configured with 5 read capacity units (RCUs) and 5 write capacity units (WCUs). The function performs both reads and writes. Which optimization will MOST effectively reduce throttling errors while maintaining performance?

A.Increase the RCUs and WCUs of the table to 50 each
B.Switch the DynamoDB table to on-demand capacity mode
C.Implement a DynamoDB Accelerator (DAX) cluster for caching reads
D.Increase Lambda function memory to 1024 MB
AnswerB

Switching to on-demand capacity mode allows DynamoDB to automatically scale read and write throughput based on the actual traffic patterns generated by the Lambda function. This eliminates ProvisionedThroughputExceededException errors by dynamically adjusting capacity, ensuring the table can handle unpredictable or spiky workloads without manual intervention or capacity planning. It directly resolves throttling issues stemming from insufficient provisioned capacity.

Why this answer

The DynamoDBProvisionedThroughputExceededException errors indicate that the Lambda function is exceeding the provisioned write capacity of 5 WCUs. Switching to on-demand capacity mode eliminates the need to manage throughput, automatically scaling to handle the workload without throttling. This directly resolves the root cause—capacity exhaustion—without requiring manual adjustments or architectural changes.

Exam trap

The trap here is that candidates often confuse read throttling with write throttling and reach for DAX (a read cache) or assume that increasing Lambda resources will solve database-level throughput issues, when the real fix is to match the database capacity mode to the workload pattern.

How to eliminate wrong answers

Option A is wrong because simply increasing RCUs and WCUs to 50 is a manual, reactive fix that does not address the root cause of unpredictable traffic patterns; it may still lead to throttling if the workload spikes beyond the new limit, and it incurs unnecessary cost if the average usage is lower. Option C is wrong because DAX caches reads only, but the errors are DynamoDBProvisionedThroughputExceededException, which primarily affects writes (the function writes processed data); caching reads does not reduce write throttling. Option D is wrong because increasing Lambda memory only increases CPU and network throughput, not DynamoDB capacity; it does not resolve the throttling errors caused by exceeding the table's write capacity.

163
MCQeasy

A developer is using Amazon S3 to host a static website. The website returns 403 Forbidden errors. The bucket policy allows public read access. What is the most likely cause?

A.The bucket's 'Block public access' settings are enabled.
B.The bucket has an ACL that denies read access.
C.The bucket policy does not include the 's3:GetObject' action.
D.The bucket policy is not correctly attached to the bucket.
AnswerA

This is the correct reason. Amazon S3 Block Public Access settings provide a critical security layer that overrides all other access control mechanisms, including bucket policies and ACLs, to prevent public access to S3 buckets and objects. If these settings are enabled at either the account or bucket level, they will effectively block any public read access, even if a bucket policy explicitly grants 's3:GetObject' permissions to the public, thereby preventing the static website from loading.

Why this answer

The most likely cause is that the bucket's 'Block public access' settings are enabled. Even if the bucket policy explicitly grants public read access, S3's Block Public Access settings act as an overarching security override that denies all public requests, resulting in a 403 Forbidden error. These settings are enabled by default for new buckets and can be applied at the account or bucket level, making them a common pitfall.

Exam trap

The trap here is that candidates often focus on the bucket policy syntax or ACLs, overlooking the fact that S3's Block Public Access settings can silently override all public permissions, even when the policy is perfectly written.

How to eliminate wrong answers

Option B is wrong because if an ACL denies read access, it would conflict with the bucket policy, but the question states the bucket policy allows public read access, and S3 evaluates both ACLs and policies; however, Block Public Access settings are a more common and immediate cause. Option C is wrong because the bucket policy is stated to allow public read access, which implicitly includes the 's3:GetObject' action; if it were missing, the error would be Access Denied, but the policy is correctly configured per the question. Option D is wrong because if the bucket policy were not correctly attached, the bucket would not have any policy to evaluate, leading to default private access (403), but the question explicitly says the policy allows public read access, implying it is attached; the issue is the Block Public Access override.

164
MCQmedium

Refer to the exhibit. A developer runs the AWS CLI command for an EC2 instance. The instance is in the 'running' state, but the application hosted on it is not reachable. What should the developer check first?

A.Check the security group rules for inbound traffic.
B.Check the ELB health check settings.
C.Check the instance status checks in the EC2 console.
D.Verify the instance ID is correct.
AnswerA

Security groups act as a virtual stateful firewall for EC2 instances, controlling both inbound and outbound traffic. If the security group associated with the EC2 instance does not have an inbound rule explicitly allowing traffic on the required port (e.g., HTTP on port 80, SSH on port 22) from the source IP address range of the client, the connection will be blocked. This typically results in a "Connection refused" or timeout error, even if the instance is running and healthy, making it the most common cause of network connectivity issues.

Why this answer

When an EC2 instance is in the 'running' state but the application is unreachable, the most common initial cause is that the Security Group associated with the instance does not allow inbound traffic on the application's port (e.g., port 80 or 443). Security groups act as stateful firewalls at the instance level, and by default, they block all inbound traffic unless explicitly allowed.

Exam trap

Candidates often confuse the instance state ('running') with network accessibility. An instance can be fully operational and healthy, but still completely unreachable from the internet if the security group rules or network ACLs are misconfigured.

How to eliminate wrong answers

Option B is wrong because ELB health check settings are only relevant if the instance is behind an Elastic Load Balancer, and the question does not mention an ELB; even if it were, the health check would fail due to the same security group issue, making it a secondary check. Option C is wrong because instance status checks verify the OS and hypervisor health (e.g., system reachability), and since the instance is 'running' and the application is unreachable, the issue is likely at the network layer, not the instance's operational status. Option D is wrong because verifying the instance ID is a basic validation step that would have been done before running the CLI command; if the ID were incorrect, the CLI command would have failed with an error, not left the instance running but unreachable.

165
MCQhard

A developer ran the above CLI command to describe an EC2 instance. The instance is running but the developer cannot connect to it via SSH. Which additional step should the developer take to troubleshoot the connectivity issue?

A.Check the AMI ID to ensure it is a valid Linux AMI
B.Check the instance's network interfaces for a public IP
C.Check the instance status checks in the EC2 console
D.Check the security group rules associated with the instance
AnswerD

Security groups function as stateful virtual firewalls that control inbound and outbound traffic for an EC2 instance. For SSH connectivity, an inbound rule must explicitly permit TCP traffic on port 22 from the source IP address range (e.g., `0.0.0.0/0` for anywhere, or a specific IP) to the instance. If no such rule exists, or if the source IP is not allowed, the connection attempt will be silently dropped at the security group level, preventing SSH from establishing.

Why this answer

Security group rules control inbound traffic to the instance. If the security group does not allow SSH (port 22) from the developer's IP, the connection will fail even if the instance is running and has a public IP. The describe-instances command output includes security group names and IDs, allowing the developer to verify the rules.

Option A is wrong because a valid AMI does not guarantee network connectivity. Option B is wrong because the instance may have a public IP but still be unreachable if the security group blocks SSH. Option C is wrong because instance status checks indicate the OS and instance health, not network-level access.

166
Multi-Selecteasy

Which TWO approaches can be used to optimize costs for an Amazon DynamoDB table with predictable read/write patterns? (Select TWO.)

Select 2 answers
A.Increase the read capacity units to avoid throttling.
B.Use provisioned capacity with auto scaling.
C.Use DynamoDB global tables for multi-region replication.
D.Use DynamoDB Accelerator (DAX) to cache read results.
E.Use on-demand capacity mode.
AnswersB, D

Provisioned capacity with auto scaling is the most cost-effective approach for predictable workloads. DynamoDB uses CloudWatch alarms on utilization metrics (e.g., 70% of consumed capacity) to automatically increase or decrease your provisioned read and write capacity units, so you only pay for what your traffic actually requires. However, note that scaling happens gradually, so you must set sensible minimums and maximums to avoid both throttling and underused capacity.

Why this answer

Option B is correct because provisioned capacity with auto scaling lets you set a target utilization and have Application Auto Scaling adjust read/write capacity units to match predictable traffic, so you pay only for the capacity you actually need rather than over-provisioning. Option D is correct because DAX is an in-memory cache for DynamoDB that serves eventually consistent reads from memory, reducing the number of read capacity units consumed on the table and lowering cost for read-heavy, predictable workloads. Option A is not correct because increasing read capacity units raises cost rather than optimizing it, and it addresses throttling, not cost efficiency.

Option C is not correct because global tables add multi-region replication and incur extra write and storage costs, which is a resilience feature, not a cost optimization. Option E is not correct because on-demand capacity mode is designed for unpredictable or spiky workloads and typically costs more per request than well-tuned provisioned capacity for predictable patterns.

Exam trap

DVA-C02 often tests the misconception that on-demand mode is always cheaper or that global tables reduce costs, when in fact they increase cost for resilience.

167
MCQmedium

A developer has deployed an AWS Lambda function that is triggered by an Amazon S3 event. The function processes image files and stores metadata in an Amazon DynamoDB table. CloudWatch metrics show that the function's error count has increased. The developer checks CloudWatch Logs and sees errors related to insufficient memory. The function is configured with 128 MB of memory. What should the developer do to resolve the errors?

A.Increase the function's memory to 256 MB or higher.
B.Increase the function's timeout to 30 seconds.
C.Reduce the size of the images being uploaded to S3.
D.Move the DynamoDB write operation to an asynchronous invocation.
AnswerA

An "out-of-memory" error directly indicates that the allocated memory for the Lambda function is insufficient to perform its operations, such as image processing which can be memory-intensive. Increasing the memory allocation directly addresses this by providing more RAM for the function to utilize during execution. Furthermore, AWS Lambda's execution environment scales CPU power proportionally with memory allocation, meaning higher memory also grants more vCPUs, accelerating image processing and reducing overall execution time.

Why this answer

The error is caused by insufficient memory, which directly impacts the CPU and execution resources allocated to the Lambda function. Increasing the memory allocation to 256 MB or higher provides more CPU throughput and memory, resolving the out-of-memory errors without requiring code changes.

Exam trap

The trap here is that candidates confuse memory errors with timeout errors and incorrectly choose to increase the timeout, but the logs explicitly state insufficient memory, not duration limits.

How to eliminate wrong answers

Option B is wrong because increasing the timeout does not address memory exhaustion; timeout errors occur when execution duration exceeds the limit, not when memory is insufficient. Option C is wrong because reducing image sizes is a workaround that may not be feasible or controlled by the developer, and it does not fix the underlying resource allocation issue. Option D is wrong because moving the DynamoDB write to an asynchronous invocation does not reduce memory consumption during image processing; the function still needs enough memory to process the image in memory before any write occurs.

168
MCQeasy

A developer invoked a Lambda function and saw the above output. What is the root cause of the error?

A.The Lambda function lacks permission to access the event payload.
B.The function code expects a property that is missing from the event payload.
C.The Lambda function's handler name is incorrect.
D.The Lambda function timed out.
AnswerB

The observed error, likely a TypeError indicating an attempt to access a property (e.g., 'length') on an 'undefined' value, strongly suggests that a nested property or object expected by the function's code was not present in the incoming event payload. When a JavaScript or Python function tries to dereference a property on an 'undefined' or non-existent object, the runtime throws an exception because the path to the desired property does not exist, causing the execution to halt.

Why this answer

The correct answer is B: the function code expects a property that is missing from the event payload. In Lambda, when the handler accesses a key on the parsed event object (e.g., event['detail'] or event.detail) that does not exist, the runtime raises a KeyError or TypeError, which surfaces as an invocation error in the response. This is a data-shape mismatch between what the code reads and what the caller sent, not an infrastructure or configuration failure.

Option A is wrong because payload access is not gated by IAM permissions; the event is always delivered to the handler. Option C is wrong because an incorrect handler name produces a Runtime.HandlerNotFound or 'handler does not exist' error before any code runs. Option D is wrong because a timeout returns Task timed out after X seconds rather than a missing-property error.

169
MCQmedium

A development team is using AWS CodeCommit as a source repository and CodeBuild for build automation. They want to trigger a build automatically whenever a pull request is created or updated in the repository. Which configuration should they use?

A.Configure an S3 event notification on the repository
B.Configure a webhook in CodeCommit to trigger CodeBuild
C.Use Amazon EventBridge to capture CodeCommit events and trigger CodeBuild
D.Create a CodePipeline that polls CodeCommit for changes
AnswerC

Amazon EventBridge is the correct and recommended service for integrating CodeCommit with other AWS services based on repository events. CodeCommit automatically publishes various events, including repository pushes, pull request creations, and state changes, to EventBridge. A specific EventBridge rule can then be configured to filter for desired CodeCommit event patterns and directly invoke AWS CodeBuild as a target, initiating a build process in response to code changes or pull request activity. This provides a robust, serverless, and event-driven integration.

Why this answer

The correct option is C: use Amazon EventBridge to capture CodeCommit events and trigger CodeBuild. CodeCommit emits pull request state-change events (e.g., pullRequestCreated and pullRequestSourceBranchUpdated) to the default EventBridge bus, and an EventBridge rule can match those events and invoke CodeBuild as a target, which is the supported way to start builds on pull request creation or updates. Option A is wrong because S3 event notifications apply to S3 buckets, not CodeCommit repositories.

Option B is wrong because CodeCommit webhooks are not a native trigger mechanism for CodeBuild in this pull request scenario. Option D is wrong because CodePipeline polling detects branch commits, not pull request creation/update events, and polling is not event-driven.

170
MCQhard

A developer is optimizing an API Gateway REST API that uses Lambda integration. The response times are high, and CloudWatch logs show that the Lambda function has cold starts frequently. The function is written in Java and uses a large library. What is the MOST effective optimization?

A.Rewrite the function in Node.js to reduce cold start time.
B.Increase the Lambda function's memory allocation to 3008 MB.
C.Enable provisioned concurrency on the Lambda function.
D.Use the AWS SDK for Java 2.x to reduce initialization time.
AnswerC

Enabling provisioned concurrency on a Lambda function explicitly pre-initializes a specified number of execution environments, keeping them warm and ready to process invocations immediately. This mechanism directly bypasses the cold start process, as the runtime and function code are already loaded and initialized before an invocation arrives. For API Gateway integrations, this ensures consistent, low-latency responses by eliminating the variable startup time associated with cold starts, which is critical for user-facing applications.

Why this answer

The most effective optimization is C: enabling provisioned concurrency on the Lambda function, because it pre-initializes execution environments so that invocations are served by already-warm instances, eliminating the cold starts that CloudWatch logs show are frequent. This directly addresses the Java runtime's heavy initialization cost caused by the large library, without changing application code. Option A is a major rewrite that may reduce cold start duration but does not guarantee elimination and changes the technology stack.

Option B increases memory and can proportionally speed initialization, but cold starts would still occur. Option D may modestly improve Java initialization, but it does not prevent cold starts the way provisioned concurrency does.

171
Matchingmedium

Match each AWS deployment strategy to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Switch between two environments

Gradual traffic shifting

Update instances incrementally

Immediate full deployment

Equal percentage increments

Why these pairings

Common deployment strategies include Rolling, Blue/Green, and Canary. Rolling deploys incrementally, Blue/Green switches between environments, and Canary tests with a small subset. Distractors often confuse these definitions.

172
MCQmedium

A developer deployed a new version of a Lambda function that processes S3 events. After deployment, some S3 events are not being processed. The CloudWatch Logs show no errors. What is the most likely cause?

A.The Lambda function has a syntax error.
B.The S3 bucket's event notification still points to the old Lambda function.
C.The Lambda function alias is not pointing to the new version.
D.The S3 events are being throttled by Lambda.
AnswerB

When a new Lambda function version is deployed, S3 event notifications configured to invoke a specific Lambda function (by ARN) will continue to invoke the previously configured version or $LATEST if no specific version was specified. To direct S3 events to a new specific version, the S3 event notification configuration on the bucket must be explicitly updated with the new Lambda function version ARN. This is a common operational oversight when deploying new function versions.

Why this answer

After deploying a new version of a Lambda function, the S3 bucket's event notification configuration still references the Amazon Resource Name (ARN) of the old Lambda function version or the function without a qualifier. S3 event notifications are configured to invoke a specific Lambda function ARN, and if the ARN does not point to the new version (e.g., by using an alias or the $LATEST qualifier), events will continue to be sent to the old version, which may not be processing them. Since CloudWatch Logs show no errors, the old version is likely not being invoked or is not logging, confirming the mismatch.

Exam trap

The trap here is that candidates assume deploying a new Lambda version automatically updates all event sources, but S3 event notifications are static ARN references that must be manually updated or use aliases to reflect the new version.

How to eliminate wrong answers

Option A is wrong because a syntax error would cause the Lambda function to fail during invocation, which would generate error logs in CloudWatch Logs, but the question states there are no errors. Option C is wrong because Lambda function aliases are optional; if the S3 event notification is configured to invoke the function directly without an alias (e.g., using the function ARN without a qualifier), the alias not pointing to the new version is irrelevant. Option D is wrong because Lambda throttling would produce a 'ThrottleReason' metric in CloudWatch and error logs (e.g., 429 TooManyRequestsException), but the question states no errors are present.

173
Multi-Selectmedium

A developer is troubleshooting a slow-running application that uses ElastiCache for Redis as a caching layer. The application frequently reads and writes data to the cache. Which TWO actions should the developer take to improve cache performance?

Select 2 answers
A.Use optimized data structures like hashes instead of strings for complex data.
B.Configure the cache to use LRU eviction policy.
C.Disable persistence by setting appendonly to no.
D.Increase the number of shards to distribute data.
E.Enable ElastiCache auto scaling to adjust the number of nodes.
AnswersA, E

Employing optimized data structures such as Redis hashes, instead of storing complex data as serialized strings, significantly enhances performance. Hashes allow for direct field access, reducing the need for costly serialization/deserialization operations and parsing overhead on the application side. This leads to more efficient memory usage and faster CPU processing for read and write operations, as data can be accessed and manipulated with O(1) average time complexity, directly improving application responsiveness.

Why this answer

Using optimized data structures like hashes instead of strings reduces memory and CPU overhead for complex data, improving cache performance. Option E is correct because enabling ElastiCache auto scaling allows the cluster to adjust the number of nodes based on demand, preventing performance degradation during traffic spikes. Option B is incorrect: LRU eviction policy helps manage memory when full but is not a performance optimization for read/write operations.

Option C is incorrect: disabling persistence (appendonly no) improves write performance but is not the primary issue for a slow application and may affect data durability. Option D is incorrect: increasing shards distributes data but does not directly improve performance if the bottleneck is CPU or memory; auto scaling is a more targeted solution.

Exam trap

A common trap is to think that disabling persistence (appendonly) is the best way to improve write performance in Redis, but in a caching scenario, persistence may not be the main bottleneck.

174
Multi-Selectmedium

A developer is troubleshooting a slow Amazon DynamoDB table. The table has a read capacity of 1000 RCU and a write capacity of 500 WCU. The application frequently reads the same item. Which TWO actions can improve read performance?

Select 2 answers
A.Increase the read capacity units (RCU) to 2000.
B.Add a Global Secondary Index (GSI) on the frequently read attribute.
C.Decrease the write capacity units (WCU) to 250.
D.Implement DynamoDB Accelerator (DAX) for caching.
E.Use eventually consistent reads instead of strongly consistent reads.
AnswersD, E

DynamoDB Accelerator (DAX) is an in-memory cache specifically designed for DynamoDB, providing microsecond response times for read-heavy workloads. By caching frequently accessed items, DAX significantly reduces the latency of read operations and offloads read traffic from the underlying DynamoDB table. This direct caching mechanism is highly effective at improving application responsiveness for 'slow' reads.

Why this answer

DynamoDB Accelerator (DAX) is an in-memory cache that can reduce read latency for frequently accessed items from milliseconds to microseconds, offloading read traffic from the table and improving performance without requiring a capacity increase. Option E is correct because eventually consistent reads consume half the RCU of strongly consistent reads (0.5 RCU vs 1 RCU per 4 KB item) and return data faster, which is suitable when the application can tolerate slightly stale data for the same item.

Exam trap

The trap here is that candidates often choose to increase RCU (Option A) as a knee-jerk reaction to slow reads, overlooking that caching (DAX) and consistency model changes are more cost-effective and targeted solutions for repeated reads of the same item.

175
MCQmedium

A company runs a Node.js application on AWS Elastic Beanstalk. The application is experiencing high latency. The developer suspects the database queries are slow. Which step should the developer take first to diagnose the issue?

A.Migrate the database to Amazon DynamoDB for better performance.
B.Enable enhanced health reporting and monitor CloudWatch metrics for database connection time.
C.Add database indexing to improve query performance.
D.Increase the instance size to improve performance.
AnswerB

Elastic Beanstalk's enhanced health reporting provides detailed system and application metrics, including crucial database connection statistics, directly to Amazon CloudWatch. Monitoring "database connection time" specifically allows for direct diagnosis of latency issues between the application instances and the database. This approach provides actionable data to pinpoint whether the database itself, network latency, or application-level connection pooling is the bottleneck, enabling targeted resolution.

Why this answer

The first step should be to enable enhanced health reporting and monitor CloudWatch metrics for database connection time. This provides visibility into the application's performance and helps identify if the database is indeed the bottleneck.

Exam trap

DVA-C02 often tests the principle of diagnosing before acting, with distractors that suggest immediate fixes like migration or scaling without evidence.

How to eliminate wrong answers

Option A is wrong because migrating to DynamoDB is a drastic step that should not be taken before diagnosing the issue; it may not solve the problem and could introduce new complexities. Option C is wrong because adding indexes is a potential fix but should be based on diagnosis; without confirming slow queries, it could be premature. Option D is wrong because increasing instance size is a scaling action that may not address the root cause and could be costly if the issue is elsewhere.

176
MCQmedium

A developer is troubleshooting a CloudFront distribution that serves static content from an S3 bucket. Users in some geographic locations report slow load times. The developer checks the CloudFront metrics and sees a high number of cache misses. What is the MOST likely cause?

A.The CloudFront distribution is configured with Price Class 100, which uses only the US and Europe edge locations.
B.The S3 bucket is configured with signed URLs for access.
C.The CloudFront distribution is not configured to compress objects.
D.The object TTL is set to a very low value (e.g., 0 seconds).
AnswerD

Setting an object's Time To Live (TTL) to a very low value, such as 0 seconds, explicitly instructs CloudFront to either not cache the object at all or to revalidate it with the origin for virtually every subsequent request. This configuration directly prevents CloudFront from effectively serving content from its edge caches, forcing each user request to reach the origin. Consequently, this results in a consistently high cache miss ratio, significantly degrading performance and increasing origin load.

Why this answer

A very low or zero TTL (e.g., 0 seconds) causes CloudFront to treat every request as a cache miss, forcing it to fetch the object from S3 on each request. This increases latency for users, especially in distant geographic locations, because the edge location must repeatedly retrieve the object from the origin. Setting a reasonable TTL allows edge locations to serve cached content and reduces origin fetches.

Exam trap

DVA-C02 often tests the confusion between cache misses and latency causes — candidates blame Price Class or compression for high miss rates, when the real driver is a TTL of 0 or a no-cache origin header.

How to eliminate wrong answers

Option A is wrong because Price Class 100 only limits which edge locations are used (US, Canada, Europe); while it can affect latency for users outside those regions, it does not cause a high number of cache misses — the metric would show high latency, not high miss rate. Option B is wrong because signed URLs control access authorization, not cacheability; CloudFront can cache responses to signed URL requests as long as the cache key and TTL allow it. Option C is wrong because compression reduces payload size and improves transfer speed but does not affect whether an object is cached or the cache hit ratio.

177
MCQmedium

An application running on Amazon EC2 instances behind an Application Load Balancer (ALB) is experiencing increased latency. The developer suspects the ALB is the bottleneck. How can the developer confirm this using CloudWatch metrics?

A.Monitor the HealthyHostCount metric and ensure it is equal to the number of instances.
B.Monitor the SurgeQueueLength metric and look for sustained high values.
C.Monitor the TargetResponseTime metric and compare it to the client's perspective.
D.Monitor the RequestCount metric and check if it exceeds the ALB's limit.
AnswerC

The TargetResponseTime metric measures the time elapsed from when the Application Load Balancer (ALB) sends a request to a registered target until the target responds. While important for understanding backend performance, this metric only accounts for the time after the request leaves the ALB. It does not include any potential delays or queuing time the request might experience within the ALB before being forwarded, thus not fully representing the client's total perceived latency.

Why this answer

To determine if the ALB or the backend targets are causing the latency, the developer should monitor the 'TargetResponseTime' metric. This metric measures the time elapsed (in seconds) from when the request leaves the ALB until a response from the target is received. If 'TargetResponseTime' is low but the client-side latency is high, the bottleneck lies within the ALB itself or the network.

If 'TargetResponseTime' is high, the bottleneck is the backend EC2 instances. 'SurgeQueueLength' is a Classic Load Balancer metric and is not available on ALBs.

Exam trap

AWS frequently tests your ability to distinguish between Classic Load Balancer (CLB) metrics (like SurgeQueueLength and SpilloverCount) and Application Load Balancer (ALB) metrics (like TargetResponseTime). Remember that ALBs do not have a request queue metric.

How to eliminate wrong answers

Option A is wrong because HealthyHostCount only indicates the number of registered instances that pass health checks; it does not measure ALB load or queuing, so it cannot confirm the ALB as the bottleneck. Option C is wrong because TargetResponseTime measures the time taken by the backend targets to respond, not the ALB's internal processing or queuing delay; comparing it to client-perceived latency would highlight backend issues, not ALB overload. Option D is wrong because RequestCount alone does not have a fixed 'limit' that triggers latency; ALBs scale automatically based on request load, and exceeding a limit would cause errors, not necessarily increased latency.

178
MCQmedium

A developer is using Amazon CloudFront to serve static content from an S3 bucket. Users are reporting that they see outdated content. The CloudFront distribution has a default TTL of 24 hours. What is the MOST efficient way to serve updated content immediately?

A.Create a CloudFront invalidation for the updated objects.
B.Disable and re-enable the CloudFront distribution.
C.Update the object key in the S3 bucket.
D.Change the default TTL to 0.
AnswerA

Creating a CloudFront invalidation is the precise and recommended method to force edge locations to remove specific cached objects. When an object in the origin is updated, an invalidation request explicitly tells CloudFront to delete the old version from all edge caches, compelling subsequent user requests for that object to fetch the newest version directly from the origin. This ensures immediate content freshness across the entire distribution without affecting other cached items.

Why this answer

Creating a CloudFront invalidation for the updated objects is the most efficient way to immediately serve updated content because it forces CloudFront to fetch the latest version from the origin, bypassing the cached copies. This method is targeted and does not affect other cached objects, making it ideal for urgent updates.

Exam trap

DVA-C02 often tests the misconception that changing TTL settings or disabling the distribution is a quick fix for cache updates, but the most efficient and immediate method is invalidation.

How to eliminate wrong answers

Option B is wrong because disabling and re-enabling the distribution is disruptive, takes time to propagate, and is not an efficient way to update content; it also does not guarantee immediate cache clearing. Option C is wrong because updating the object key in S3 changes the URL, which would require updating all references to the content and is not efficient for immediate updates. Option D is wrong because changing the default TTL to 0 would prevent caching entirely, increasing load on the origin and latency for users, and it does not immediately invalidate existing cached objects.

179
MCQeasy

A developer uses the CloudFormation template in the exhibit to create an S3 bucket. The stack creation fails with the error 'Bucket already exists'. What is the MOST likely reason?

A.The CloudFormation template has invalid JSON syntax.
B.The bucket name is already taken by another AWS account.
C.The IAM user does not have permission to create S3 buckets.
D.The bucket name is not available in the specified region.
AnswerB

Amazon S3 bucket names are globally unique across all AWS accounts, not just within a single account or region. When a CloudFormation stack attempts to create an S3 bucket with a name that is already registered by any other AWS account worldwide, the creation will fail with a 'Bucket already exists' error. This global namespace constraint means even if the name appears available within your account's context, it might be owned by another AWS customer.

Why this answer

S3 bucket names are globally unique across all AWS accounts and regions, so if the name specified in the CloudFormation template is already in use by another account, the stack creation fails with 'Bucket already exists'. This is the most likely cause given the error message. The error is not related to syntax, IAM permissions, or region availability.

Exam trap

DVA-C02 often tests the global uniqueness of S3 bucket names versus regional resource constraints; candidates who assume the error is region-related or permission-related pick the wrong answer instead of recognizing the global namespace conflict.

How to eliminate wrong answers

Option A is wrong because invalid JSON syntax would produce a template validation error (e.g., 'Template format error'), not 'Bucket already exists'. Option C is wrong because insufficient IAM permissions would produce an 'Access Denied' error, not a bucket-name conflict. Option D is wrong because S3 bucket names are global, not region-scoped; the same name cannot be reused in any region, so the error is not about regional availability.

← PreviousPage 3 of 3 · 179 questions total

Ready to test yourself?

Try a timed practice session using only Troubleshooting and Optimization questions.