Courseiva

CCNA Dev AWS Services Questions

75 of 388 questions · Page 1/6 · Dev AWS Services topic · Answers revealed

1
MCQmedium

A developer is using Amazon S3 to store application logs. The logs are generated every hour and must be retained for 90 days. After 90 days, the logs should be deleted automatically. Which S3 lifecycle policy should the developer configure?

A.Expire objects after 30 days.
B.Transition objects to Amazon S3 Glacier after 90 days.
C.Expire objects after 90 days.
D.Transition objects to S3 Standard-IA after 30 days and expire after 90 days.
AnswerC

Implementing an S3 Lifecycle rule to Expire objects after 90 days directly addresses the requirement for automatic deletion of application logs. This action permanently removes the objects from the S3 bucket 90 days after their creation, ensuring that old logs are automatically purged. This approach optimizes storage costs and maintains data hygiene without requiring manual intervention, aligning perfectly with a deletion mandate.

Why this answer

The requirement is to delete logs after 90 days, and the S3 lifecycle 'Expire' action permanently removes objects once they reach the specified age. No transitions are needed since the logs are not required to be stored in a different storage class before deletion.

Exam trap

The trap here is that candidates often overcomplicate the solution by adding unnecessary transitions (like Option D) or confuse 'transition' with 'expiration', thinking moving to Glacier after 90 days automatically deletes the data, which it does not.

How to eliminate wrong answers

Option A is wrong because expiring objects after 30 days would delete them far earlier than the required 90-day retention period. Option B is wrong because transitioning objects to S3 Glacier after 90 days does not delete them; it only moves them to a colder storage class, and they would continue to incur storage costs indefinitely unless an expiration action is also configured. Option D is wrong because while it includes an expiration after 90 days, the transition to S3 Standard-IA after 30 days is unnecessary and adds cost; the requirement only specifies deletion after 90 days, not tiering.

2
MCQmedium

A developer is building a serverless application using AWS Lambda to process images uploaded to an S3 bucket. The Lambda function needs to resize the image and store the result in another S3 bucket. The developer notices that the Lambda function fails intermittently with timeout errors for large images. What is the MOST efficient solution to resolve this issue?

A.Increase the Lambda function timeout and memory allocation to accommodate larger images.
B.Limit the S3 event notification to only trigger for images smaller than 5 MB.
C.Refactor the Lambda function to use multi-threading for parallel processing of image chunks.
D.Use AWS Step Functions to orchestrate the image processing in smaller steps.
AnswerA

Increasing the Lambda function's memory allocation directly scales its CPU power proportionally, providing more computational resources to process larger and more complex images efficiently. Concurrently, extending the timeout allows the function sufficient time to complete computationally intensive tasks like high-resolution image resizing or complex transformations without premature termination. This direct adjustment of allocated resources and execution duration is the most straightforward solution for handling larger image files within a single Lambda invocation.

Why this answer

Increasing the Lambda function timeout and memory allocation directly addresses the root cause of the failure: large images require more processing time and memory. Lambda's CPU and I/O throughput scale proportionally with allocated memory, so raising both parameters provides the necessary resources to complete the resize operation within the function's execution environment.

Exam trap

The trap here is that candidates often overcomplicate the solution by considering orchestration or parallel processing (Options C and D), when the simplest and most efficient fix is to adjust the Lambda function's resource limits, which directly control execution time and processing capacity.

How to eliminate wrong answers

Option B is wrong because limiting S3 event notifications to images smaller than 5 MB does not resolve the issue for larger images; it merely avoids processing them, which is not a solution for handling large images as required. Option C is wrong because Lambda functions run in a single-threaded execution environment by default, and multi-threading for image chunks is not supported; even with provisioned concurrency, image processing libraries like Pillow are not designed for parallel chunk processing within a single invocation. Option D is wrong because AWS Step Functions adds orchestration overhead and does not increase the per-invocation timeout or memory limits of the Lambda function; the underlying timeout error would still occur when a single step processes a large image.

3
MCQmedium

A developer is building a serverless application using AWS Lambda and Amazon API Gateway. The API must support different HTTP methods (GET, POST, PUT, DELETE) for the same resource path. The developer wants to define the API in a single Lambda function that can handle all methods without additional mapping configuration. Which Lambda integration type should the developer use?

A.Lambda proxy integration
B.Lambda custom integration
C.AWS service integration
D.HTTP integration
AnswerA

Lambda proxy integration is the correct choice because it forwards the complete client request, including HTTP method, headers, query string parameters, and body, directly to the integrated Lambda function as a single input event. This allows the Lambda function to act as a unified handler, inspecting the 'httpMethod' property within the event object to implement distinct logic for different operations (e.g., GET, POST, PUT, DELETE) on the same resource path. This approach significantly simplifies API Gateway configuration by eliminating the need for separate integration request mappings per method.

Why this answer

Lambda proxy integration (option A) is correct because it allows a single Lambda function to handle all HTTP methods (GET, POST, PUT, DELETE) for the same resource path without additional mapping configuration. In this integration type, API Gateway passes the entire client request (method, headers, query parameters, body) as a JSON event to the Lambda function, and the function must return a response in a specific format that includes status code, headers, and body. This eliminates the need for manual mapping templates or method-specific configurations.

Exam trap

The trap here is that candidates often confuse Lambda custom integration with Lambda proxy integration, thinking that custom integration provides more control, but they overlook that proxy integration is specifically designed to handle multiple HTTP methods without additional mapping configuration.

How to eliminate wrong answers

Option B (Lambda custom integration) is wrong because it requires explicit mapping templates to transform the client request into the Lambda function's input format and to transform the Lambda response back to the HTTP response, which adds configuration overhead and does not support handling all methods in a single function without additional mapping. Option C (AWS service integration) is wrong because it is designed to integrate API Gateway directly with other AWS services (e.g., DynamoDB, SQS) without invoking a Lambda function, and it does not support routing multiple HTTP methods to a single Lambda function. Option D (HTTP integration) is wrong because it is used to proxy requests to an external HTTP endpoint, not to a Lambda function, and it requires mapping templates or VPC link configurations, making it unsuitable for a serverless Lambda-based API.

4
MCQmedium

The above IAM policy is attached to an IAM role used by a Lambda function. The function tries to scan the table 'MyTable' but receives an AccessDenied error. What is the MOST likely cause?

A.The DynamoDB table does not exist.
B.The IAM role is not attached to the Lambda function.
C.The resource ARN is incorrect.
D.The policy does not include the 'dynamodb:Scan' action.
AnswerD

The `AccessDeniedException` from DynamoDB is the definitive indicator that the IAM principal (the Lambda function's execution role) attempted an API action for which it lacks explicit authorization within its attached IAM policies. If the Lambda function's code is attempting to execute the `Scan` operation, but the IAM policy only permits actions like `GetItem` or `PutItem`, then the `dynamodb:Scan` request will be implicitly denied. IAM operates on an 'explicit allow' model, meaning any action not explicitly allowed is implicitly denied.

Why this answer

The IAM policy shown in the question does not include the 'dynamodb:Scan' action. Without this action explicitly allowed, the Lambda function's role lacks permission to perform a Scan operation on the DynamoDB table, resulting in an AccessDenied error. The policy must grant the specific action required by the API call.

Exam trap

The trap here is that candidates often focus on resource ARN or table existence, overlooking that the policy must explicitly include the specific DynamoDB action (e.g., 'dynamodb:Scan') being called by the Lambda function.

How to eliminate wrong answers

Option A is wrong because if the DynamoDB table did not exist, the error would be a ResourceNotFoundException, not AccessDenied. Option B is wrong because the question states the policy is attached to an IAM role used by the Lambda function, so the role is attached; the error is due to missing permissions, not missing attachment. Option C is wrong because an incorrect resource ARN would cause an error when evaluating the policy, but the error message would typically be AccessDenied only if the ARN does not match; however, the most likely cause given the policy's missing action is the lack of 'dynamodb:Scan'.

5
MCQmedium

A developer is deploying an AWS Lambda function that needs to access an Amazon RDS for MySQL database. The function runs in a private subnet and must connect without exposing credentials in code. The database credentials are stored in AWS Secrets Manager and rotate automatically. Which approach should the developer use to retrieve the credentials securely?

A.Use an Amazon RDS IAM database authentication token generated by the Lambda execution role instead of a password.
B.Embed the credentials in the Lambda deployment package and use AWS CodeArtifact to store the package securely.
C.Grant the Lambda execution role permission to call secretsmanager:GetSecretValue and retrieve the secret at runtime using the AWS SDK.
D.Store the database password in a Lambda environment variable and enable encryption with an AWS KMS key.
AnswerC

Attaching an IAM policy that allows secretsmanager:GetSecretValue to the Lambda execution role lets the function retrieve the current secret with temporary credentials. This avoids hardcoded credentials, respects rotation, and follows least-privilege access, so it is the secure and recommended approach.

Why this answer

Granting the Lambda execution role secretsmanager:GetSecretValue and retrieving the secret at runtime with the AWS SDK is the secure way to use rotating credentials without embedding them. The function always reads the current secret value, and access is controlled through IAM rather than static configuration.

Exam trap

The trap here is thinking that KMS-encrypted environment variables are equivalent to Secrets Manager, when environment variables cannot follow automatic rotation and remain static.

6
MCQeasy

Refer to the exhibit. An IAM policy is attached to an IAM user. The user tries to upload a file to s3://my-bucket/confidential/report.pdf. What will happen?

A.The upload fails because the Deny statement overrides the Allow.
B.The upload succeeds because the Deny statement applies only to the bucket, not the user.
C.The upload fails because the policy does not allow PutObject on that path.
D.The upload succeeds because the Allow statement grants PutObject.
AnswerA

AWS IAM policy evaluation logic dictates that an explicit Deny statement always takes precedence over any Allow statement, even if the Allow statement would otherwise grant the requested permission. In this scenario, despite an Allow for s3:PutObject, the presence of a Deny for the same action on the bucket ensures the upload operation is blocked. This fundamental rule prioritizes security by preventing unintended access, making the upload fail.

Why this answer

IAM policy evaluation logic dictates that an explicit Deny always overrides any Allow. In this scenario, the Deny statement denies `s3:PutObject` on the path `arn:aws:s3:::my-bucket/confidential/*`, which matches the user's upload target `s3://my-bucket/confidential/report.pdf`. Even though the Allow statement grants `s3:PutObject` on `arn:aws:s3:::my-bucket/*`, the explicit Deny takes precedence, causing the upload to fail.

Exam trap

The trap here is that candidates often assume an Allow statement alone determines access, forgetting that an explicit Deny in the same policy overrides any Allow, regardless of the order in which the statements appear.

How to eliminate wrong answers

Option B is wrong because the Deny statement applies to the user via the attached IAM policy, not to the bucket; IAM policies are resource-based and affect the user's permissions directly, so the Deny blocks the user's action. Option C is wrong because the policy does allow PutObject on that path via the Allow statement (`my-bucket/*` includes `my-bucket/confidential/report.pdf`), but the Deny overrides it. Option D is wrong because while the Allow statement grants PutObject, the explicit Deny on the same action and path overrides it, preventing the upload from succeeding.

7
MCQmedium

Refer to the exhibit. A developer attached the IAM policy to a Lambda function's execution role. The function reads items from a DynamoDB table that uses AWS KMS customer managed key (CMK) for encryption at rest. When the function tries to read an item, it receives an access denied error. What is the cause?

A.The DynamoDB table is not encrypted with a KMS key.
B.The policy allows kms:Decrypt on all resources but the CMK key policy may not grant access.
C.The policy does not allow dynamodb:GetItem on the table.
D.The DynamoDB table does not exist.
AnswerB

AWS KMS employs a two-layer authorization model for Customer Managed Keys (CMKs), requiring both an IAM policy and the KMS key policy to grant access. While the provided IAM policy explicitly allows `kms:Decrypt` on all resources (`*`), the specific CMK's key policy might not include the calling principal or its account in its statement, thereby denying the final decryption permission required to access the DynamoDB data.

Why this answer

The IAM policy grants kms:Decrypt on all resources, but DynamoDB uses AWS KMS customer managed keys (CMKs) for encryption at rest. Even if the IAM policy allows the action, the CMK's key policy must also grant the Lambda execution role access to use the key. If the key policy does not include a statement allowing the Lambda role to perform kms:Decrypt, the request fails with an access denied error, regardless of the IAM policy.

Exam trap

The trap here is that candidates assume an IAM policy allowing kms:Decrypt on all resources is sufficient, forgetting that KMS customer managed keys have their own key policies that must also grant access.

How to eliminate wrong answers

Option A is wrong because the question explicitly states the table uses a KMS CMK for encryption at rest, so the table is encrypted. Option C is wrong because the IAM policy includes dynamodb:GetItem on the specific table ARN, so the action is allowed by IAM. Option D is wrong because the error is access denied, not resource not found (HTTP 404), and the question implies the table exists.

8
MCQmedium

A Lambda function receives events from EventBridge. The developer wants failed invocations to be retried and then stored for later analysis if retries are exhausted. Which configuration should be used?

A.Enable API Gateway access logging
B.Configure EventBridge retry policy and a dead-letter queue
C.Increase reserved concurrency to zero
D.Store events in CloudFormation outputs
AnswerB

Configuring an EventBridge retry policy ensures that events are re-attempted if the initial Lambda invocation fails, improving resilience. Pairing this with a dead-letter queue (DLQ) for the EventBridge target is crucial. If all retries are exhausted and the Lambda function still fails to process an event, EventBridge will send that event to the specified DLQ, preventing data loss and allowing for subsequent investigation and reprocessing of failed events.

Why this answer

EventBridge supports a configurable retry policy (with a maximum event age up to 24 hours and up to 185 retries by default) and can route events that exceed the retry limit to an Amazon SQS dead-letter queue (DLQ). This ensures failed invocations are retried automatically and, if all retries are exhausted, the event is stored durably in the DLQ for later analysis or reprocessing.

Exam trap

The trap here is that candidates may confuse the Lambda function's own DLQ configuration (which applies to synchronous and asynchronous invocations) with EventBridge's rule-level retry policy and DLQ, but EventBridge manages retries and DLQ delivery independently of the Lambda service's built-in retry mechanism.

How to eliminate wrong answers

Option A is wrong because API Gateway access logging captures HTTP request/response data for REST or HTTP APIs, not Lambda invocation failures from EventBridge, and it does not provide retry or dead-letter storage. Option C is wrong because setting reserved concurrency to zero would prevent the Lambda function from executing at all, causing every invocation to fail immediately without retries or storage. Option D is wrong because CloudFormation outputs are used to export stack resource information (e.g., ARNs, endpoints) for cross-stack references, not for storing event data or handling failed invocations.

9
Multi-Selectmedium

Which TWO AWS services can be used to decouple components of a microservices architecture?

Select 2 answers
A.Amazon Route 53
B.Amazon EventBridge
C.Elastic Load Balancing
D.Amazon CloudWatch
E.Amazon SQS
AnswersB, E

Amazon EventBridge is a serverless event bus service that enables event-driven architectures, significantly decoupling service components. It allows services to publish events to a central bus, which then routes them to various targets based on defined rules, without direct knowledge of the consumers. This pattern ensures producers and consumers operate independently, enhancing scalability, fault tolerance, and maintainability by eliminating direct point-to-point integrations.

Why this answer

Amazon EventBridge (Option B) is correct because it provides a serverless event bus that decouples microservices by allowing them to communicate asynchronously via events. Services publish events to EventBridge, and other services consume them without direct coupling, enabling loose coupling and scalability.

Exam trap

The trap here is that candidates often confuse Elastic Load Balancing (a synchronous traffic distributor) with asynchronous decoupling services, or mistakenly think Route 53's routing capabilities can decouple services, when in fact only message/event-based services like SQS and EventBridge achieve true decoupling.

10
MCQmedium

A developer is building a serverless application using AWS SAM. The application includes an Amazon API Gateway endpoint with a Lambda function that processes user uploads. The developer wants to enable API caching in the development stage to speed up repeated requests, but disable caching in the production stage. What is the most efficient way to achieve this?

A.Configure caching in the SAM template using the CacheClusterEnabled property and use CloudFormation conditions to enable it only in the dev stage.
B.Create two separate SAM templates, one for dev with caching and one for prod without.
C.Enable caching in the API Gateway console after each deployment for the dev stage.
D.Use a custom CloudFormation resource to toggle caching based on a parameter.
AnswerA

This is the most robust and automated approach. The AWS::Serverless::Api resource in a SAM template can define Stage properties, including CacheClusterEnabled. By integrating a CloudFormation Condition that evaluates a StageName parameter, caching can be enabled specifically for the dev stage while remaining disabled for prod, all within a single, version-controlled template. This ensures consistent, environment-specific deployments via CI/CD pipelines.

Why this answer

AWS SAM extends AWS CloudFormation, allowing you to use CloudFormation conditions to conditionally enable the `CacheClusterEnabled` property on the `AWS::ApiGateway::Stage` resource. By defining a condition that evaluates to true only for the dev stage (e.g., based on a parameter like `StageName`), you can enable caching in dev and disable it in prod within a single SAM template, avoiding duplication and manual steps.

Exam trap

The trap here is that candidates may think caching must be configured per-deployment manually (Option C) or that separate templates are required (Option B), missing the power of CloudFormation conditions to conditionally enable features within a single SAM template.

How to eliminate wrong answers

Option B is wrong because creating two separate SAM templates introduces unnecessary duplication and maintenance overhead; the same effect can be achieved with a single template using CloudFormation conditions, which is more efficient. Option C is wrong because manually enabling caching in the API Gateway console after each deployment is error-prone, not repeatable, and violates infrastructure-as-code best practices; it also requires post-deployment steps that can be forgotten. Option D is wrong because using a custom CloudFormation resource to toggle caching is overly complex and introduces additional Lambda functions or custom logic when the native `CacheClusterEnabled` property combined with conditions already provides a straightforward, built-in solution.

11
MCQhard

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application stores user session data in an Amazon ElastiCache for Redis cluster. Recently, users have been experiencing intermittent session timeouts and data loss. The developer examines the application logs and finds errors indicating that the Redis cluster is returning 'READONLY You can't write against a read-only replica.' The ElastiCache cluster is configured as a Redis replication group with one primary and two replicas. The application's connection code uses the primary endpoint. What is the most likely cause of this issue?

A.The ElastiCache cluster has been scaled down to a single node, causing the primary to become unavailable.
B.A failover event occurred, and the application is still trying to write to the old primary node, which is now a replica.
C.The ElastiCache security group is blocking write traffic to the primary endpoint.
D.The Redis cluster mode is enabled, and the application is not using the correct cluster endpoint.
AnswerB

During a failover event in an ElastiCache for Redis replication group, one of the replicas is promoted to become the new primary, and the original primary node is demoted to a replica role. Redis replicas are configured by default to reject write operations, returning a READONLY error. If the application's client-side connection or cached endpoint still points to the old primary node, it will attempt to write to what is now a replica, resulting in the observed READONLY error.

Why this answer

The READONLY error occurs when attempting to write to a Redis replica node. In a replication group with one primary and two replicas, a failover event can promote a replica to become the new primary while the old primary becomes a replica. If the application's connection code uses the primary endpoint (which is a DNS name), DNS caching or a long TTL may cause the application to continue resolving to the old primary's IP address, now a replica.

Subsequent write requests to this replica will fail with the READONLY error, causing intermittent session timeouts and data loss. Option B correctly identifies this scenario. Option A is incorrect because scaling down to a single node would not produce this specific error.

Option C is incorrect because security groups would block all traffic, not just writes. Option D is incorrect because cluster mode (sharding) is unrelated to the primary-replica configuration causing the error.

12
MCQhard

A developer is building a serverless application using AWS Lambda that processes messages from an Amazon SQS queue. The queue receives about 100 messages per second, and each message takes about 30 seconds to process. The Lambda function is configured with a reserved concurrency of 10. The developer notices that messages are frequently being sent to the dead-letter queue (DLQ) after three failed processing attempts. The Lambda function's execution role has the necessary permissions to read from the SQS queue and write to the DLQ. The SQS queue's visibility timeout is set to 60 seconds, and the Lambda function's timeout is set to 60 seconds. What is the most likely cause of the messages being sent to the DLQ?

A.The SQS queue is not configured to use long polling, causing the Lambda function to receive empty responses and waste time.
B.The reserved concurrency of 10 is too low to handle the incoming message rate, causing messages to be repeatedly retried until they exceed the maxReceiveCount.
C.The Lambda function timeout is too short for the processing time required.
D.The DLQ is incorrectly configured to receive all failed messages after the first attempt.
AnswerB

A reserved concurrency of 10 means the Lambda function can only process 10 messages concurrently at any given time. If the incoming message rate from SQS significantly exceeds this limit, new Lambda invocations will be throttled. Messages that cannot be processed immediately will remain in the SQS queue, their visibility timeout will expire, and they will become visible again for another processing attempt. This cycle of retries continues, incrementing the ReceiveCount for each message, until the maxReceiveCount defined in the SQS queue's redrive policy is exceeded, at which point the message is moved to the Dead-Letter Queue.

Why this answer

With a reserved concurrency of 10, the Lambda function can process at most 10 messages concurrently. Since each message takes 30 seconds, the maximum throughput is about 10 messages per 30 seconds = ~0.33 messages per second, far below the incoming rate of 100 messages per second. Messages that are not processed will become visible again after the visibility timeout (60 seconds).

They will be retried, but due to the low concurrency, they will likely fail again, eventually exceeding the maxReceiveCount (default 3) and being sent to the DLQ. Option A is incorrect because long polling reduces empty responses but does not address the throughput limitation. Option C is incorrect because the 60-second timeout is sufficient for 30-second processing.

Option D is incorrect because the DLQ triggers after the maxReceiveCount, not after the first attempt.

13
MCQeasy

A developer is building a serverless application that uses Amazon DynamoDB. The application needs to retrieve an item by its primary key frequently. Which DynamoDB API call should the developer use to achieve the lowest latency?

A.Scan
B.Query
C.GetItem
D.BatchGetItem
AnswerC

The GetItem operation is the most efficient and recommended method for retrieving a single item from a DynamoDB table. It directly accesses the item using its complete primary key (partition key, and sort key if applicable), resulting in minimal latency and consuming the fewest provisioned read capacity units (RCUs). This direct lookup mechanism makes it ideal for precise, single-item data retrieval.

Why this answer

The GetItem API call is the most efficient way to retrieve a single item by its primary key in DynamoDB, as it directly accesses the item using the hash key (and optionally the sort key) with consistent, single-digit millisecond latency. Unlike Scan or Query, GetItem does not need to evaluate any conditions or filter through other items, making it the lowest-latency option for this specific use case.

Exam trap

The trap here is that candidates often confuse Query with GetItem, assuming Query is always faster because it uses a key condition, but Query still requires evaluating the sort key and can return multiple items, whereas GetItem is the only API optimized for a single-item primary key lookup.

How to eliminate wrong answers

Option A is wrong because Scan reads every item in the table or index and then filters out the results, which incurs high latency and consumes significant read capacity, especially on large tables. Option B is wrong because Query retrieves all items with a given partition key value and can return multiple items, requiring additional processing and potentially higher latency than a direct key-based lookup. Option D is wrong because BatchGetItem is designed for retrieving multiple items in a single operation, but it adds overhead for batching and may return partial results, making it slower than GetItem for a single item retrieval.

14
MCQeasy

The above CLI output shows the versioning status of an S3 bucket. A developer wants to enable MFA Delete on the bucket. What should the developer do?

A.Use the aws s3api put-bucket-acl command with MFA token.
B.Use the aws s3api put-bucket-versioning command with the --mfa parameter.
C.Enable Object Lock on the bucket, which automatically enables MFA Delete.
D.Use the aws s3api put-bucket-policy command to require MFA.
AnswerB

Using `aws s3api put-bucket-versioning` with `--mfa` supplies the required authentication code alongside the versioning configuration, satisfying S3's rule that MFA Delete can only be enabled by the bucket owner via a signed request including both the MFA device serial and a valid code.

Why this answer

The `aws s3api put-bucket-versioning` command with the `--mfa` parameter is the correct way to enable MFA Delete on an S3 bucket. The `--mfa` parameter supplies the MFA token (serial number + code) required for this high-security operation, as MFA Delete can only be toggled by the bucket owner using multi-factor authentication.

Exam trap

The trap here is that candidates confuse MFA Delete with requiring MFA for access (via bucket policy) or assume Object Lock automatically enables MFA Delete, but MFA Delete is a distinct versioning setting that must be explicitly enabled using the `put-bucket-versioning` API with the `--mfa` parameter.

How to eliminate wrong answers

Option A is wrong because `put-bucket-acl` manages Access Control Lists (ACLs), not versioning or MFA Delete; MFA Delete is a versioning sub-feature, not an ACL property. Option C is wrong because Object Lock does not automatically enable MFA Delete; they are independent features — Object Lock provides write-once-read-many (WORM) protection, while MFA Delete requires explicit versioning configuration with an MFA token. Option D is wrong because `put-bucket-policy` sets resource-based IAM policies, not versioning or MFA settings; requiring MFA in a bucket policy controls access but does not enable the MFA Delete feature on the bucket itself.

15
MCQhard

A company is using AWS CloudFormation to deploy infrastructure. The developer wants to create a custom resource that runs a Lambda function during stack creation and update. What must the developer do to ensure the custom resource works correctly?

A.The Lambda function must send a response to an S3 pre-signed URL.
B.The Lambda function must be defined in the same CloudFormation template.
C.The Lambda function must return a JSON object with the desired output.
D.The Lambda function must be written in Python.
AnswerA

When a CloudFormation custom resource invokes a Lambda function, CloudFormation provides a unique, time-limited S3 pre-signed URL within the event data. The Lambda function is absolutely required to send a JSON response to this specific URL, indicating the success or failure of the custom resource operation. This response mechanism allows CloudFormation to asynchronously track the status and retrieve any output attributes from the custom resource's execution, which is crucial for stack progression.

Why this answer

AWS CloudFormation custom resources require the Lambda function to send a response to an S3 pre-signed URL to signal completion. CloudFormation waits for this response to proceed with stack operations; without it, the stack creation or update will time out and fail.

Exam trap

The trap here is that candidates assume the Lambda function's return value is automatically captured by CloudFormation, but in reality, the function must explicitly send a response to the pre-signed URL to signal completion.

How to eliminate wrong answers

Option B is wrong because the Lambda function does not need to be defined in the same CloudFormation template; it can be referenced via an ARN from another stack or account. Option C is wrong because the Lambda function must send a response to the pre-signed URL using an HTTPS PUT request, not simply return a JSON object from the function invocation. Option D is wrong because the Lambda function can be written in any supported runtime (e.g., Node.js, Python, Java, Go), not exclusively Python.

16
MCQmedium

A developer is building a REST API using Amazon API Gateway and wants to validate the incoming request body against a JSON schema before passing the request to the backend Lambda function. Which API Gateway feature should the developer use?

A.Request validation
B.Mapping templates
C.Integration request
D.Stage variables
AnswerA

Amazon API Gateway's request validation feature allows developers to define a JSON schema for the request body, as well as specify required headers, query string parameters, and path parameters. This mechanism ensures that incoming requests conform to the API's expected structure and data types before they reach the backend integration. By rejecting malformed requests early, it enhances API security and reduces unnecessary processing by downstream services.

Why this answer

API Gateway's request validation feature allows you to define a JSON schema (using JSON Schema Draft 4) for the request body and automatically reject requests that do not conform before they reach the backend. This offloads validation from the Lambda function, reducing cold start overhead and ensuring only valid payloads are processed. The developer can configure this in the API Gateway console or via the OpenAPI specification.

Exam trap

The trap here is that candidates often confuse request validation with mapping templates, assuming that mapping templates can validate the request body, but mapping templates only transform data and do not enforce schema constraints.

How to eliminate wrong answers

Option B is wrong because mapping templates transform the request body or parameters into a different format (e.g., from JSON to XML) for the backend, but they do not perform schema-based validation. Option C is wrong because the integration request defines how API Gateway passes the request to the backend (e.g., HTTP method, headers, query strings) and can include mapping templates, but it does not natively validate the request body against a JSON schema. Option D is wrong because stage variables are key-value pairs used to configure deployment stages (e.g., Lambda function aliases, endpoint URLs) and have no role in request body validation.

17
MCQmedium

A developer is writing a Lambda function in Node.js that reads a secret from AWS Secrets Manager on every invocation. The function runs frequently, and the developer wants to minimize both latency and the number of Secrets Manager API calls. Which approach should the developer take?

A.Call GetSecretValue inside the handler and cache the value in a variable declared in the global scope of the module.
B.Call GetSecretValue inside the handler on every invocation and enable AWS X-Ray tracing to reduce the API call latency.
C.Call GetSecretValue in the handler but set the AWS SDK maxRetries to 0 to reduce the number of API calls.
D.Store the secret as a Lambda environment variable and remove all Secrets Manager permissions from the function role.
AnswerA

Variables declared outside the handler persist across warm invocations of the same execution environment. Fetching the secret once and reusing the cached value reduces Secrets Manager calls and avoids repeated network latency on subsequent warm invocations while still working correctly on cold starts.

Why this answer

Declaring the secret variable in the global scope and populating it inside the handler lets warm Lambda execution environments reuse the value across invocations. This minimizes Secrets Manager GetSecretValue calls and latency while preserving correct behavior on cold starts, when the variable is repopulated.

Exam trap

The trap here is assuming that any code inside the Lambda handler runs only once per function, when in fact the handler runs on every invocation while global scope persists across warm starts.

18
Drag & Dropmedium

Drag and drop the steps to create a Lambda function that processes S3 events in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First set up permissions, then code, create function, configure trigger, and test.

19
MCQeasy

A developer is deploying a new version of an AWS Lambda function using the AWS CLI. The developer wants to ensure that the new version is stable before routing all traffic to it. The developer has already published version 1 and version 2 of the function. The developer wants to send 10% of the traffic to version 2 and 90% to version 1. The developer then plans to gradually increase the traffic to version 2. Which approach should the developer use?

A.Use the Lambda function's versioning feature to set the traffic weight directly on the function.
B.Create a Lambda alias named 'prod' and update the alias's routing configuration to send 10% traffic to version 2 and 90% to version 1.
C.Configure the API Gateway endpoint to route 10% of requests to version 2 and 90% to version 1.
D.Create a new alias and assign the traffic weights to the versions in the alias configuration.
AnswerB

A Lambda alias with routing configuration splits invocation traffic between two published versions by percentage, so 10% to version 2 and 90% to version 1 is achieved, then adjusted gradually. Aliases provide the weighted shifting that the scenario requires.

Why this answer

AWS Lambda aliases allow you to create a named reference to a specific function version and configure weighted routing between two versions. By creating an alias (e.g., 'prod') and setting its routing configuration to send 10% of traffic to version 2 and 90% to version 1, the developer can gradually shift traffic. This is the standard approach for canary deployments with Lambda.

The alias can be updated to adjust weights as confidence in the new version grows.

Exam trap

DVA-C02 often tests the confusion between Lambda versions and aliases, where candidates might think traffic weights can be set on versions directly, or that API Gateway is required for weighted routing.

How to eliminate wrong answers

Option A is wrong because Lambda versioning alone does not support traffic weights; weights are configured on aliases, not directly on versions. Option C is wrong because API Gateway can route traffic to different Lambda versions, but it requires more complex configuration and does not provide the native weighted alias feature; it is also not the simplest approach. Option D is wrong because it is essentially the same as option B but less specific; however, the key is that the alias must be created and then its routing configuration set.

Option D is not incorrect per se, but it is vague and does not specify the alias name or the exact configuration, whereas option B is precise and correct. In the context of the exam, option B is the best answer.

20
MCQmedium

A developer must locally test a SAM-based Lambda function with an API event before deployment. Which tool command family is designed for this?

A.AWS SAM CLI local invoke/start-api
B.AWS Shield Advanced CLI
C.AWS Organizations policy simulator
D.Amazon Inspector SBOM export
AnswerA

The AWS SAM CLI `local invoke` and `local start-api` commands are specifically designed for testing serverless applications locally. `sam local invoke` allows developers to execute a single Lambda function with a provided event payload, simulating a direct invocation. `sam local start-api` launches a local HTTP server that emulates Amazon API Gateway, enabling testing of Lambda functions integrated with API Gateway by making actual HTTP requests to the local endpoint, providing a comprehensive local testing environment for SAM-based applications.

Why this answer

The AWS SAM CLI provides the `local invoke` and `local start-api` commands specifically for testing Lambda functions locally with simulated API Gateway events before deployment. `sam local start-api` creates a local HTTP server that mimics API Gateway, allowing developers to send requests to their Lambda functions as if they were deployed, while `sam local invoke` directly invokes the function with a specified event payload. This is the only tool family designed for local testing of SAM-based Lambda functions with API events.

Exam trap

The trap here is that candidates may confuse the AWS SAM CLI with other AWS CLI tools or services, mistakenly thinking that general-purpose CLI commands or unrelated security tools can perform local Lambda testing with API events.

How to eliminate wrong answers

Option B is wrong because AWS Shield Advanced CLI is a tool for managing DDoS protection services, not for testing Lambda functions or API events locally. Option C is wrong because AWS Organizations policy simulator is used to test IAM and SCP policies for multi-account environments, not for local Lambda or API Gateway testing. Option D is wrong because Amazon Inspector SBOM export is used to generate a software bill of materials for vulnerability assessment, not for testing Lambda functions or API events.

21
MCQmedium

An API Gateway REST API invokes Lambda synchronously. Clients receive 502 responses after a deployment, but Lambda logs show a successful business operation. What is the most likely issue?

A.The Lambda execution role lacks dynamodb:PutItem
B.The Lambda proxy integration response format is invalid
C.The API cache TTL is too short
D.The API stage has X-Ray tracing enabled
AnswerB

In a Lambda proxy integration, API Gateway expects the Lambda function's response to adhere to a specific JSON structure, including `statusCode`, `headers`, and a `body` field (which must be a string). If the Lambda function returns a response that deviates from this required format—for example, missing the `statusCode` or `body` fields, or if the `body` is not a string—API Gateway cannot properly parse it. Consequently, API Gateway will fail to construct a valid HTTP response for the client and will return a 500 Internal Server Error.

Why this answer

Lambda proxy integration requires the response to be in a specific JSON format: `{"statusCode": ..., "headers": ..., "body": ...}`. If the Lambda function returns a plain string or an object missing these keys, API Gateway cannot map it to an HTTP response, resulting in a 502 Internal Server Error. The successful business operation in logs confirms the Lambda code ran correctly, but the malformed response format causes the gateway error.

Exam trap

The trap here is that candidates see 'successful business operation' in logs and assume the Lambda is fine, overlooking that API Gateway proxy integration enforces a strict response contract, not just any valid return value.

How to eliminate wrong answers

Option A is wrong because a missing `dynamodb:PutItem` permission would cause a 403 Forbidden or 500 error from Lambda, not a 502, and the logs would show an access denied exception, not a successful operation. Option C is wrong because API cache TTL affects cached responses and latency, not the response format or 502 errors; a short TTL would cause more frequent cache misses, not gateway errors. Option D is wrong because enabling X-Ray tracing adds tracing headers and logs but does not alter the response format or cause 502 errors; it is purely a monitoring feature.

22
MCQeasy

A developer needs to store configuration parameters securely for a Lambda function. The parameters include database credentials and API keys. Which AWS service should be used?

A.AWS Systems Manager Parameter Store
B.AWS Secrets Manager
C.Amazon DynamoDB with encryption
D.Amazon S3 with server-side encryption
AnswerB

AWS Secrets Manager stores database credentials and API keys as encrypted secrets, with native rotation via Lambda and fine-grained IAM access control. This directly satisfies the stem's requirement to store configuration parameters securely, unlike plaintext environment variables or unencrypted Parameter Store strings.

Why this answer

AWS Secrets Manager is the correct choice because it is purpose-built for securely storing, rotating, and managing sensitive configuration parameters such as database credentials and API keys throughout their lifecycle. It offers automatic rotation of secrets with built-in integration for Amazon RDS, Redshift, and DocumentDB, and enforces fine-grained access control via IAM policies. This makes it the most suitable service for the developer's requirement of securely storing and managing database credentials and API keys for a Lambda function.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store (Option A) with Secrets Manager because both can store strings, but Parameter Store lacks automatic rotation and secret-specific lifecycle management, making it unsuitable for credentials that require regular rotation as per security best practices.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Parameter Store is a general-purpose parameter store for configuration data like instance IDs or AMI IDs, but it lacks native automatic rotation of secrets and does not provide the same level of secret-specific features (e.g., cross-account access, versioning with staging labels) that Secrets Manager offers for sensitive credentials. Option C is wrong because Amazon DynamoDB with encryption is a NoSQL database service designed for storing application data, not for managing secrets; it requires custom code to handle secret rotation, access auditing, and lifecycle management, adding unnecessary complexity and security risk. Option D is wrong because Amazon S3 with server-side encryption is an object storage service that can store encrypted files, but it does not provide native secret rotation, automatic credential generation, or integration with AWS services like RDS for password management, making it a poor fit for dynamic secrets like database credentials and API keys.

23
MCQhard

A company is using AWS CodePipeline to automate their CI/CD pipeline. The pipeline includes a stage that runs a set of integration tests using AWS CodeBuild. The tests require access to a database running on a private subnet in a VPC. The CodeBuild project is configured to use a managed compute image. How can the CodeBuild project access the database?

A.Place the CodeBuild project in a public subnet and use a NAT gateway to route traffic to the private subnet.
B.Configure the CodeBuild project to use a custom VPC with the appropriate subnet and security group.
C.Set up a VPC peering connection between the CodeBuild VPC and the database VPC.
D.Create a VPC endpoint for the database service and attach it to the CodeBuild project.
AnswerB

Configuring the CodeBuild project to use a custom VPC with the appropriate subnet and security group is the correct solution. This allows CodeBuild to launch its build environments directly within your specified Amazon VPC, enabling it to access private resources like an Amazon RDS database using their private IP addresses. By placing the CodeBuild environment in a private subnet and associating it with a security group that permits outbound traffic to the database's security group, secure and private network communication is established.

Why this answer

CodeBuild projects using managed compute images run in an AWS-managed VPC by default, which cannot access resources in a customer VPC. By configuring the CodeBuild project to use a custom VPC with the appropriate subnet and security group, the build environment is launched directly into that VPC, enabling it to reach the database on the private subnet without needing a NAT gateway or internet access.

Exam trap

The trap here is that candidates assume a NAT gateway or VPC peering is required to bridge network boundaries, but they overlook that CodeBuild's default environment is isolated from the customer VPC, and the correct solution is to launch the build directly into the customer VPC using a custom VPC configuration.

How to eliminate wrong answers

Option A is wrong because placing a CodeBuild project in a public subnet is not a valid configuration; CodeBuild projects are not assigned to subnets directly—they run in an AWS-managed environment unless a custom VPC is specified, and using a NAT gateway would not grant access to a private subnet from the managed VPC. Option C is wrong because VPC peering connects two VPCs, but the CodeBuild project's default environment is not in a customer VPC, so there is no VPC to peer with; even if a custom VPC were used, peering would be unnecessary since the database is already in the same VPC. Option D is wrong because VPC endpoints are used to privately connect to AWS services (e.g., S3, DynamoDB) via the AWS network, not to access a customer-managed database running on an EC2 instance or RDS in a private subnet.

24
MCQeasy

A developer needs to securely store database credentials for a Lambda function. The credentials must be automatically rotated every 30 days. Which service should be used?

A.AWS Key Management Service (KMS)
B.AWS Secrets Manager
C.AWS Systems Manager Parameter Store
D.AWS CloudHSM
AnswerB

AWS Secrets Manager is purpose-built for securely storing, managing, and retrieving sensitive information such as database credentials, API keys, and other secrets. Its primary advantage for database credentials is the automatic rotation capability, which integrates directly with various AWS services and databases to periodically change credentials without requiring application downtime. This service also provides fine-grained access control, auditing, and automatic encryption of stored secrets, making it the ideal solution for this requirement.

Why this answer

AWS Secrets Manager is the correct choice because it is specifically designed to securely store, manage, and automatically rotate database credentials and other secrets. It supports built-in rotation with AWS Lambda, allowing you to set a rotation schedule (e.g., every 30 days) without custom infrastructure. This service integrates directly with Amazon RDS, Redshift, and DocumentDB for seamless credential rotation.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store (which can store secrets with encryption) with AWS Secrets Manager, but Parameter Store lacks native automatic rotation, making it unsuitable for the 30-day rotation requirement.

How to eliminate wrong answers

Option A is wrong because AWS KMS is a key management service for creating and controlling encryption keys, not for storing or rotating secrets like database credentials. Option C is wrong because AWS Systems Manager Parameter Store can store secrets but does not natively support automatic rotation of credentials; it requires custom Lambda functions and manual setup for rotation. Option D is wrong because AWS CloudHSM provides dedicated hardware security modules for cryptographic operations, not a service for storing or rotating application secrets.

25
Multi-Selecteasy

A developer is building a microservices architecture using Amazon ECS with Fargate. The services need to communicate with each other. Which TWO AWS services can be used for service discovery?

Select 2 answers
A.Amazon ECR
B.AWS Cloud Map
C.Elastic Load Balancing
D.AWS Systems Manager Parameter Store
E.Amazon Route 53
AnswersB, E

AWS Cloud Map is a fully managed service discovery solution specifically designed for cloud-native applications, including microservices. It allows developers to register any application resource, such as containers, EC2 instances, or serverless functions, with custom names. Services can then discover the network locations of these registered resources using either API calls or standard DNS queries, making it highly flexible for dynamic environments.

Why this answer

AWS Cloud Map is a cloud resource discovery service that allows you to define custom names for your application resources and maintain the updated location of these dynamically changing resources. For Amazon ECS with Fargate, you can register each service instance with Cloud Map, and other services can then discover them via DNS queries or API calls, enabling seamless inter-service communication in a microservices architecture.

Exam trap

The trap here is that candidates often confuse Elastic Load Balancing (which handles traffic distribution) with service discovery, or they assume that any AWS service with 'registry' or 'store' in its name (like ECR or Parameter Store) can be used for discovering running services, when in fact only Cloud Map and Route 53 provide the necessary DNS and API-based discovery capabilities.

26
MCQmedium

A company is running a monolithic application on an EC2 instance. The application currently stores session state in local memory on the instance. The company plans to scale the application horizontally by adding more instances behind a load balancer. What change is required to ensure that session state is preserved across requests?

A.Store session data in Amazon S3 and retrieve it on each request.
B.Increase the EC2 instance size to handle more sessions per instance.
C.Use Amazon ElastiCache to store session state externally.
D.Use an Amazon RDS database to store session state.
AnswerC

Amazon ElastiCache provides a highly performant, in-memory data store, making it an ideal solution for externalizing session state. By storing session data in ElastiCache (e.g., Redis or Memcached), all EC2 instances can access a centralized, low-latency session store, enabling seamless horizontal scaling and high availability. This approach ensures that user sessions persist even if individual application instances are added, removed, or fail, promoting a truly stateless application design.

Why this answer

Amazon ElastiCache provides a managed, in-memory caching service (e.g., Redis or Memcached) that can store session state externally. By moving session data out of the EC2 instance's local memory and into a shared, low-latency data store, all instances behind the load balancer can access the same session state, ensuring persistence across requests regardless of which instance handles the request.

Exam trap

The trap here is that candidates often choose Option D (RDS) because they think a database is the only reliable external store, overlooking that ElastiCache is purpose-built for high-speed, ephemeral data like session state, while RDS introduces unnecessary latency and overhead for this use case.

How to eliminate wrong answers

Option A is wrong because Amazon S3 is an object storage service with high latency per request (typically 100-200 ms) and is not designed for frequent, sub-millisecond read/write operations required for session state; it would introduce unacceptable performance degradation. Option B is wrong because increasing the EC2 instance size only addresses vertical scaling (more sessions per instance) but does not solve the fundamental problem of session state being lost when a request is routed to a different instance in a horizontally scaled environment. Option D is wrong because Amazon RDS is a relational database with higher latency and connection overhead compared to in-memory caches; while it could technically store session state, it is not optimized for the high-throughput, low-latency access patterns of session management and would introduce unnecessary cost and complexity.

27
MCQhard

An organization has a Lambda function that processes messages from an Amazon SQS queue. The function is configured with a reserved concurrency of 5. The SQS queue has a visibility timeout of 30 seconds. The Lambda function takes an average of 45 seconds to process each message. What is the likely behavior of this setup?

A.The Lambda function will be throttled due to reserved concurrency.
B.The Lambda function will process messages successfully with no issues.
C.Messages will be processed multiple times because they become visible again before the function completes.
D.The Lambda function will automatically increase its processing speed.
AnswerC

This option correctly identifies the problem: if the SQS visibility timeout is configured to be shorter than the time required for the Lambda function to fully process a message, the message will become visible again in the queue. Consequently, another Lambda invocation, or even the same one after completing its current task, can retrieve and process the identical message. This leads to duplicate processing, which can cause data inconsistencies, increased costs, and unexpected application behavior.

Why this answer

The Lambda function takes 45 seconds to process a message, but the SQS queue's visibility timeout is only 30 seconds. Because the processing time exceeds the visibility timeout, the message will become visible again in the queue after 30 seconds and can be received by another Lambda invocation before the first one finishes. This leads to duplicate processing.

To prevent this, the SQS visibility timeout should be configured to be at least 6 times the Lambda function's timeout.

Exam trap

Candidates often mistakenly believe that AWS Lambda automatically manages or extends the SQS visibility timeout during execution. In reality, Lambda does not extend the timeout; it only deletes the message from the queue after the function successfully completes. If the function is still running when the visibility timeout expires, the message becomes visible to other consumers.

How to eliminate wrong answers

Option A is wrong because reserved concurrency of 5 limits the number of concurrent invocations, but it does not cause throttling here; the function is not being invoked beyond that limit. Option B is wrong because the mismatch between visibility timeout (30s) and processing time (45s) will cause messages to become visible again, leading to duplicate processing, not successful processing with no issues. Option D is wrong because Lambda does not automatically increase its processing speed; processing time is determined by the function's code and runtime, not by the invocation configuration.

28
Multi-Selecteasy

A developer is building a REST API using API Gateway and Lambda. The API must be secured using a Lambda authorizer. Which THREE steps are necessary to implement the Lambda authorizer? (Choose THREE.)

Select 3 answers
A.Configure the API Gateway method to use the Lambda authorizer.
B.Return a JSON Web Token (JWT) from the authorizer function.
C.Create a Lambda function that validates the token and returns an IAM policy.
D.Grant API Gateway permission to invoke the Lambda authorizer function.
E.Generate an API key and distribute it to clients.
AnswersA, C, D

After creating and configuring a Lambda authorizer, the crucial next step is to associate it with the specific API Gateway methods that require authorization. This configuration tells API Gateway to invoke the designated Lambda authorizer function before forwarding the request to the backend integration, ensuring that the incoming request's identity or token is validated. Without this explicit link, the authorizer would exist but never be utilized by the API endpoint.

Why this answer

The API Gateway method must be explicitly configured to use the Lambda authorizer as the authorization mechanism. This is done by setting the method's Authorization type to the Lambda authorizer's logical name in the API Gateway console or via the REST API's `authorizationType` property set to `CUSTOM` and referencing the authorizer's ID. Without this configuration, API Gateway will not invoke the authorizer function for incoming requests.

Exam trap

The trap here is that candidates confuse the token validation logic inside the authorizer with the output format, mistakenly thinking the authorizer returns a JWT or API key, when in fact it must return an IAM policy document for API Gateway to enforce authorization.

29
MCQhard

A developer is designing a serverless application that processes user-uploaded images. The images are uploaded to an S3 bucket, which triggers a Lambda function to create a thumbnail and store metadata in DynamoDB. The thumbnail creation is CPU-intensive and can take up to 10 seconds. The developer wants to minimize costs and ensure that the thumbnail is created as soon as possible. Which approach should the developer choose?

A.Use AWS Step Functions to orchestrate the Lambda function and DynamoDB update.
B.Use an ECS Fargate task to process the images, triggered by S3 events.
C.Use S3 event notifications to directly invoke the Lambda function.
D.Use an SQS queue between S3 and Lambda to buffer requests.
AnswerC

S3 event notifications provide a native, highly efficient mechanism to directly invoke an AWS Lambda function whenever specific object events occur, such as object creation. This approach offers the simplest integration pattern, minimizing configuration and operational overhead. It ensures minimal latency between the S3 event and the Lambda execution, making it highly responsive, and is extremely cost-effective as you only pay for the Lambda compute duration and S3 storage.

Why this answer

S3 event notifications directly invoke the Lambda function asynchronously, which is the simplest, fastest, and most cost-effective approach for this use case. The Lambda function's 15-minute timeout easily accommodates the 10-second thumbnail creation, and direct invocation eliminates the cost and latency of additional intermediate services like SQS or Step Functions, ensuring the thumbnail is processed as soon as the image is uploaded.

Exam trap

Candidates often overcomplicate serverless architectures by adding SQS queues or Step Functions by default. While SQS is excellent for smoothing out traffic spikes (buffering) and Step Functions is great for complex workflows, they introduce additional latency and cost. For immediate, simple processing of individual uploads, direct S3-to-Lambda asynchronous invocation is the most optimal and cost-effective choice.

How to eliminate wrong answers

Option A is wrong because AWS Step Functions would introduce unnecessary orchestration overhead and cost, as the workflow is a simple single-step process (create thumbnail and store metadata) that does not require state management or retry logic. Option B is wrong because ECS Fargate tasks incur higher costs and startup latency compared to Lambda, and are overkill for a short-lived, CPU-intensive task that fits within Lambda's timeout limits. Option D is wrong because adding an SQS queue between S3 and Lambda introduces buffering latency and additional cost, which contradicts the requirement to create the thumbnail 'as soon as possible' and does not improve performance for a single-event trigger.

30
Multi-Selecthard

A developer is using Amazon S3 to store sensitive data. The compliance team requires that all objects be encrypted at rest using server-side encryption with a customer-managed key (SSE-KMS). Which THREE steps must the developer take to enforce this requirement? (Choose THREE.)

Select 3 answers
A.Create an AWS KMS customer-managed key.
B.Configure the bucket ACL to require encryption.
C.Add a bucket policy that denies PutObject if the x-amz-server-side-encryption header is not set to 'aws:kms'.
D.Enable S3 default encryption with SSE-S3.
E.Set the bucket's default encryption to SSE-KMS using the customer-managed key.
AnswersA, C, E

To implement Server-Side Encryption with AWS KMS (SSE-KMS) for sensitive data, creating an AWS KMS customer-managed key (CMK) is a fundamental prerequisite. This key provides the developer with full control over the encryption process, including key policies, rotation, and audit trails, which is crucial for meeting stringent compliance requirements. Without a CMK, the enhanced security and control offered by SSE-KMS cannot be leveraged for data protection.

Why this answer

SSE-KMS requires a customer-managed AWS KMS key to encrypt objects at rest. By creating a customer-managed key, the developer gains control over key rotation, access policies, and audit trails, which satisfies the compliance team's requirement for server-side encryption with a customer-managed key.

Exam trap

The trap here is that candidates often confuse S3 default encryption (which can be set to SSE-KMS) with bucket policies that enforce encryption headers, but the question requires both the key creation (A) and the enforcement mechanisms (C and E) to fully satisfy the compliance requirement.

31
MCQhard

A developer is building a serverless application that uses AWS Step Functions to orchestrate multiple AWS Lambda functions. The workflow involves three steps: validate input, process data, and store results. The developer notices that the workflow occasionally fails due to transient errors in the process data step. The developer wants to implement error handling so that the workflow retries the process data step up to three times with an exponential backoff. Additionally, if all retries fail, the workflow should send a notification to an Amazon SNS topic and transition to a failure state. The developer has defined the state machine in Amazon States Language (ASL). How should the developer configure the state machine?

A.Write custom retry logic inside the Lambda function code and catch exceptions there.
B.Modify the IAM execution role to allow the state machine to call SNS and then use a ResultPath to handle errors.
C.In the process data state definition, add a Retry field with MaxAttempts: 3 and BackoffRate: 2, and add a Catch field that transitions to a failure state and sends an SNS notification.
D.Add a Retry field at the workflow level and a Catch field at the workflow level.
AnswerC

This option correctly leverages AWS Step Functions' native error handling and retry mechanisms. Adding a `Retry` field to the specific state definition allows for automatic retries with exponential backoff (`BackoffRate: 2`) and a maximum number of attempts (`MaxAttempts: 3`), enhancing the workflow's resilience against transient failures. Subsequently, a `Catch` field provides a robust fallback mechanism, directing the workflow to a designated failure state and enabling an SNS notification for operational awareness after all retries are exhausted.

Why this answer

In Amazon States Language (ASL), retry and error handling are configured per-state, not at the workflow level. The process data state should include a Retry block with MaxAttempts: 3 and BackoffRate: 2 (which produces exponential backoff: 1s, 2s, 4s by default), and a Catch block that matches the error and transitions to a failure state. The failure state can be a Task state invoking SNS Publish, or the Catch can route to a state that publishes to SNS before ending in a Fail state.

Exam trap

DVA-C02 often tests the misconception that Retry and Catch can be defined at the workflow (top) level in ASL — they cannot; they must be attached to individual Task, Parallel, or Map states.

How to eliminate wrong answers

Option A is wrong because implementing retry logic inside the Lambda function bypasses Step Functions' native error handling, loses visibility into retry attempts in the execution history, and doesn't leverage the state machine's declarative Retry/Catch semantics. Option B is wrong because IAM permissions alone do not implement retry or error routing — ResultPath is used to inject error info into the state output, not to handle errors or trigger retries. Option D is wrong because ASL does not support Retry or Catch at the workflow (top-level) scope; these fields are only valid within individual state definitions.

32
MCQmedium

A developer is debugging an AWS Lambda function that processes messages from an Amazon SQS queue. The function is failing with an error when processing certain messages. The developer wants to isolate the failed messages for later analysis without losing them. What should the developer do?

A.Publish the failed messages to an SNS topic for later processing.
B.Log the error and delete the message from the queue.
C.Increase the visibility timeout of the SQS queue.
D.Configure a dead-letter queue (DLQ) for the SQS queue.
AnswerD

Configuring a dead-letter queue (DLQ) for the SQS queue is the standard and most robust solution for handling message processing failures. When a Lambda function fails to process a message a specified number of times (defined by the maxReceiveCount on the redrive policy), SQS automatically moves that message to the DLQ. This isolates problematic messages for later inspection and debugging, prevents them from continuously blocking the main queue, and ensures no data is lost, allowing developers to analyze and re-process them.

Why this answer

Configuring a dead-letter queue (DLQ) for the SQS queue is the correct approach because it automatically captures messages that cannot be processed successfully after a specified number of retries (the redrive policy). This isolates the failed messages for later analysis without losing them, while allowing the function to continue processing other messages from the source queue.

Exam trap

The trap here is that candidates may think logging and deleting the message (Option B) is sufficient for debugging, but this permanently loses the message payload, whereas a DLQ preserves the message for later analysis without manual intervention.

How to eliminate wrong answers

Option A is wrong because publishing failed messages to an SNS topic would require custom code and does not provide automatic retry management or isolation; SNS is a pub/sub service, not a message retention mechanism for failed SQS messages. Option B is wrong because logging the error and deleting the message discards the message permanently, preventing later analysis of the failed message content. Option C is wrong because increasing the visibility timeout only delays when the message becomes visible again for reprocessing; it does not isolate the message or prevent it from being retried indefinitely, and it does not preserve the message for later analysis.

33
Multi-Selectmedium

A developer is building a serverless application using AWS Lambda to process images uploaded to an S3 bucket. The Lambda function needs to resize each image and store the result in another S3 bucket. Which TWO actions should the developer take to ensure the function can access the S3 buckets securely?

Select 2 answers
A.Create an IAM execution role for the Lambda function with permissions to read from the source bucket and write to the destination bucket.
B.Configure a bucket policy on the destination S3 bucket that grants the Lambda execution role s3:PutObject permission.
C.Store the AWS access key and secret key in the Lambda environment variables.
D.Assign an IAM user to the Lambda function and embed the user's access key in the function code.
E.Attach an IAM instance profile to the Lambda function.
AnswersA, B

Creating an IAM execution role is the standard and most secure method for a Lambda function to interact with other AWS services. This role defines the permissions the function assumes when invoked, allowing it to read objects from the source S3 bucket and write processed objects to the destination S3 bucket without embedding any static credentials. This adheres to the principle of least privilege, granting only necessary access.

Why this answer

Lambda functions require an IAM execution role that grants permissions to access other AWS services. By creating a role with policies that allow s3:GetObject on the source bucket and s3:PutObject on the destination bucket, the function can securely read and write images without embedding long-term credentials.

Exam trap

The trap here is that candidates often think they need to embed static credentials (access keys) in the function code or environment variables, but the AWS Well-Architected Framework mandates using IAM roles for temporary, least-privilege credentials in serverless applications.

34
MCQhard

A developer is deploying a Node.js application on AWS Lambda. The function uses the 'axios' library to call an external API. After deployment, the function times out after 3 seconds. The external API response time is normally under 500 ms. What should the developer do to resolve this issue?

A.Increase the Lambda function timeout to 10 seconds.
B.Increase the Lambda function reserved concurrency.
C.Remove the Lambda function from the VPC.
D.Increase the Lambda function memory to 1024 MB.
AnswerC

Removing the Lambda function from a Virtual Private Cloud (VPC) is unrelated to addressing function timeouts. Placing a Lambda function within a VPC allows it to access private resources like Amazon RDS databases or EC2 instances within that VPC. While incorrect VPC configuration (e.g., missing a NAT Gateway for internet access) can cause functions to hang and eventually time out due to network issues, the VPC configuration itself does not directly control or modify the function's execution timeout setting, which is an independent parameter.

Why this answer

When a Lambda function is configured to run inside a VPC, it loses its default internet access. If the function needs to call an external API, the connection will hang and eventually time out. Increasing the timeout (Option A) will not resolve this, as the network path is blocked.

To resolve this, the developer should either configure a NAT Gateway in the VPC or, if VPC resources are not required, remove the Lambda function from the VPC (Option C) to restore default internet access.

Exam trap

AWS often tests your understanding of Lambda VPC networking. Candidates frequently assume that increasing the timeout (Option A) or memory (Option D) will solve timeout issues, but if the root cause is a lack of internet access due to VPC configuration, the function will continue to time out regardless of the timeout limit or memory allocated.

How to eliminate wrong answers

Option B is wrong because increasing reserved concurrency only guarantees a set number of concurrent executions, which does not affect the execution duration or timeout behavior of a single invocation. Option C is wrong because removing the function from a VPC would only help if the timeout were caused by network latency or missing VPC endpoints; the problem is a timeout on an external API call, which is not inherently related to VPC configuration. Option D is wrong because increasing memory to 1024 MB allocates more CPU and network throughput, which can speed up execution but does not change the maximum allowed execution time; the function still times out at 3 seconds regardless of memory size.

35
MCQeasy

A company is using AWS CodePipeline to automate its CI/CD pipeline. The pipeline has a source stage that uses Amazon S3. The developer updates a file in the S3 bucket, but the pipeline does not start automatically. What is the MOST likely cause?

A.The IAM role for CodePipeline does not have s3:GetObject permission.
B.The pipeline is configured to use polling instead of event-based triggers.
C.Amazon S3 versioning is not enabled on the bucket.
D.AWS CloudTrail is not enabled.
AnswerC

Amazon S3 versioning is a mandatory prerequisite for CodePipeline source actions that monitor an S3 bucket for changes. CodePipeline relies on S3 event notifications, specifically s3:ObjectCreated:* events, to detect new or updated artifacts. Without versioning enabled on the S3 bucket, these critical event notifications may not be reliably generated or processed by CodePipeline, preventing the pipeline from automatically triggering upon artifact uploads.

Why this answer

CodePipeline requires S3 versioning to be enabled on the source bucket to automatically detect changes and start the pipeline. Without versioning, CodePipeline cannot uniquely identify new object versions, so it relies on manual or scheduled polling instead of event-based triggers. Enabling versioning ensures that each PUT operation generates a new version ID, which CodePipeline uses to invoke the pipeline automatically.

Exam trap

The trap here is that candidates often assume the IAM role permissions (Option A) are the root cause, but the actual requirement is S3 versioning, which is a bucket-level configuration that enables event-driven pipeline starts.

How to eliminate wrong answers

Option A is wrong because the IAM role for CodePipeline needs s3:GetObject permission to read the source artifact, but the lack of this permission would cause the pipeline to fail during execution, not prevent it from starting. Option B is wrong because polling is a fallback mechanism; the pipeline is configured to use event-based triggers by default when versioning is enabled, and the issue is that versioning is disabled, not that polling is explicitly configured. Option D is wrong because AWS CloudTrail is not required for CodePipeline to detect S3 events; CloudTrail logs API calls for auditing but does not trigger pipeline executions.

36
MCQmedium

A developer is designing a system where an S3 bucket receives uploads, and each upload triggers a Lambda function to process the file. The processed output is stored in another S3 bucket. The developer notices that sometimes the same file is processed multiple times. How can this be prevented?

A.Make the Lambda function idempotent by checking if the object has already been processed using a DynamoDB table.
B.Use an SQS FIFO queue as the event destination and enable content-based deduplication.
C.Enable S3 bucket replication to another bucket and trigger Lambda from the replica.
D.Enable S3 bucket versioning and use 's3:ObjectCreated:Put' events.
AnswerA

To ensure reliable processing despite S3's "at-least-once" event delivery model, a Lambda function must be idempotent. This is achieved by using a persistent store, such as a DynamoDB table, to record unique identifiers of processed S3 objects. Before processing an S3 event, the Lambda function checks if the object's unique identifier (e.g., bucket name + object key + version ID) already exists in the DynamoDB table. If it does, the function skips processing, preventing duplicate work and maintaining data consistency.

Why this answer

Making the Lambda function idempotent using a DynamoDB table ensures that even if the same S3 event is delivered multiple times (due to at-least-once delivery semantics) or if the same file is uploaded again, the function checks a unique identifier (such as the object key or hash) in DynamoDB before processing. If it has already been processed, the function can safely skip it. This is the standard architectural pattern for ensuring idempotency in serverless pipelines.

Exam trap

While Amazon S3 Event Notifications do support SQS FIFO queues as destinations, relying solely on SQS FIFO deduplication is insufficient. SQS FIFO deduplication has a strict 5-minute window and does not protect against Lambda retries, function timeouts, or duplicate uploads occurring outside that window. True end-to-end idempotency must be implemented at the application level (e.g., using DynamoDB).

How to eliminate wrong answers

Option B is wrong because S3 cannot send events directly to an SQS FIFO queue; S3 event notifications only support standard SQS queues, not FIFO queues. Option C is wrong because S3 replication is asynchronous and does not prevent duplicate processing; it would actually introduce additional copies and potential duplicate triggers. Option D is wrong because enabling versioning and using 's3:ObjectCreated:Put' events does not prevent duplicate invocations; versioning creates new versions but S3 still sends at-least-once notifications for each Put, so the same object version can trigger Lambda multiple times.

37
MCQmedium

A developer is building an order-processing workflow using AWS Step Functions. The state machine has a Task state that invokes a Lambda function to charge a credit card. The Lambda function occasionally returns a transient error due to a downstream payment gateway timeout. The developer must ensure the workflow automatically retries the charge up to 3 times with increasing intervals between attempts, without modifying the state machine definition for every error type. Which solution meets these requirements with the LEAST operational overhead?

A.Wrap the Lambda invocation in an SQS queue with a visibility timeout and a dead-letter queue, and have the state machine poll the queue.
B.Configure a Retry field on the Task state with ErrorEquals set to States.TaskFailed, IntervalSeconds set to 2, MaxAttempts set to 3, and BackoffRate set to 2.0.
C.Modify the Lambda function to implement its own retry loop with exponential backoff using the AWS SDK retry configuration.
D.Enable AWS X-Ray tracing on the Lambda function and use CloudWatch alarms to trigger a new state machine execution on failure.
AnswerB

The Retry field on a Task state natively supports ErrorEquals, IntervalSeconds, MaxAttempts, and BackoffRate. Setting ErrorEquals to States.TaskFailed catches Lambda function errors, and BackoffRate 2.0 doubles the wait each retry, satisfying the increasing-interval requirement without code changes or additional services.

Why this answer

Step Functions Task states support built-in retry policies through the Retry field, which accepts ErrorEquals, IntervalSeconds, MaxAttempts, and BackoffRate. Using States.TaskFailed as the error matcher catches errors returned by the Lambda function, and BackoffRate greater than 1.0 produces the required increasing intervals. This declarative approach requires no changes to the Lambda code or additional services, minimizing operational overhead.

Exam trap

The trap here is assuming that retries must be implemented in code or with additional services, when Step Functions provides a declarative Retry field with exponential backoff.

38
Multi-Selectmedium

A developer is building a RESTful API using AWS Lambda and Amazon API Gateway. The API will be accessed by external customers. The developer needs to implement authentication and authorization. Which THREE steps should the developer take to secure the API? (Choose three.)

Select 3 answers
A.Use Amazon Cognito user pools for user authentication and to generate JWT tokens.
B.Configure the API to use AWS IAM roles for authentication by passing the role ARN in the request.
C.Create a Lambda authorizer that validates a JWT token from a third-party identity provider.
D.Enable Amazon Cognito as an authorizer in the API Gateway method request settings.
E.Attach a resource policy to the API Gateway that allows only specific IAM users.
AnswersA, C, D

Amazon Cognito User Pools are a fully managed service designed for user directory management, sign-up, and sign-in. They authenticate users and issue JSON Web Tokens (JWTs) (ID, access, and refresh tokens) upon successful authentication. These JWTs can then be used by clients to authorize requests to an API Gateway, making Cognito a robust and scalable solution for user authentication in RESTful APIs.

Why this answer

Amazon Cognito user pools provide a fully managed service for user authentication, allowing users to sign in and receive JSON Web Tokens (JWT). These tokens can then be used to authorize API requests, integrating directly with API Gateway as a built-in authorizer to secure the RESTful API.

Exam trap

The trap here is that candidates may confuse IAM roles with user authentication, thinking that passing a role ARN in the request is valid, when in fact IAM authorization requires signed requests and is not suitable for external customer authentication without AWS credentials.

39
Multi-Selecteasy

A developer is building a serverless application using AWS Lambda and Amazon API Gateway. The application processes user uploads stored in an S3 bucket. The developer needs to ensure that the Lambda function can read objects from the S3 bucket. Which TWO steps should the developer take to meet this requirement? (Choose two.)

Select 2 answers
A.Set the S3 bucket's object-level permissions to allow the Lambda function.
B.Use AWS Key Management Service (KMS) to grant the Lambda function access to the S3 bucket.
C.Add a bucket policy on the S3 bucket that grants access to the Lambda function's execution role.
D.Attach an IAM policy to the Lambda execution role with permissions for s3:GetObject.
E.Create an IAM user with S3 read permissions and configure the Lambda function to assume that user.
AnswersC, D

Because the Lambda function and the S3 bucket reside in different accounts (or because the bucket owner controls the resource), a bucket policy on the S3 bucket is the resource-based policy that can explicitly grant the Lambda execution role's ARN permission to s3:GetObject. S3 evaluates both the identity-based policy on the principal (the Lambda role) and the resource-based policy, and a statement in the bucket policy that allows the role's ARN satisfies the resource authorization. This is the recommended way to enable cross-account or cross-service access because it does not require creating or rotating IAM users.

Why this answer

Option D is correct because a Lambda function accesses AWS services through its execution role, so attaching an IAM policy that allows s3:GetObject (and typically s3:ListBucket) to that role grants the function the required read access to objects in the bucket. Option C is correct because a bucket policy is a resource-based policy that can explicitly grant the Lambda function's execution role principal access to the S3 bucket and its objects, which is a valid way to authorize the read operations. Option A is incorrect because S3 object-level permissions are ACLs that grant access to AWS accounts or predefined groups, not to a Lambda function directly, and ACLs are not the recommended mechanism for Lambda-to-S3 authorization.

Option B is incorrect because KMS is used for encryption key management and does not itself grant S3 data access; KMS permissions would only matter if the objects are encrypted with a customer managed key. Option E is incorrect because Lambda functions should use an execution role, not assume an IAM user with long-term credentials, which is an insecure and unsupported pattern for this scenario.

Exam trap

DVA-C02 often tests the misconception that you can grant S3 access by setting object ACLs or by using KMS, when in fact Lambda requires an IAM execution role with the appropriate S3 permissions.

40
MCQhard

A developer is deploying a microservices architecture on Amazon ECS with Fargate. The services need to communicate with each other using service discovery. The developer wants to use AWS Cloud Map for service discovery. Which configuration is required for the services to register and discover each other?

A.Create an Application Load Balancer and register each service as a target group.
B.Create a VPC endpoint for each service.
C.Configure Security Groups to allow traffic between services.
D.Create a Cloud Map namespace and service; then configure ECS tasks to register with the service.
AnswerD

AWS Cloud Map is a cloud service discovery solution that allows you to register any application resource, such as microservices, and then define custom names for them. It provides a centralized registry that services can query using either DNS queries or an API to discover the network locations (IP addresses and ports) of other services. By configuring ECS tasks to register with a Cloud Map service, new instances automatically become discoverable, which is essential for the dynamic and ephemeral nature of microservices.

Why this answer

AWS Cloud Map requires a namespace (either HTTP or DNS) and a service resource. ECS tasks configured with service discovery can register themselves with the Cloud Map service, and other tasks can discover them via DNS queries or the Cloud Map API. Option A is incorrect because an Application Load Balancer is used for load balancing traffic, not for service discovery.

Option B is incorrect because VPC endpoints provide private connectivity to AWS services, not service registration and discovery. Option C is incorrect because Security Groups control network traffic but do not facilitate service discovery.

41
MCQeasy

A developer is writing an AWS Lambda function that processes files uploaded to an S3 bucket. The function should only be triggered when a new object is created in a specific subfolder (e.g., /uploads/). Which S3 event notification configuration should the developer use?

A.Configure the event notification with a prefix filter set to 'uploads/' and event type 's3:ObjectCreated:*'.
B.Configure a single event notification for all objects and filter on the prefix inside the Lambda function.
C.Configure the event notification using object tags to filter events.
D.Use AWS CloudTrail to detect S3 PutObject events and trigger Lambda.
AnswerA

This approach leverages Amazon S3's native event notification capabilities to precisely target specific object creation events. By setting a prefix filter to 'uploads/', the S3 bucket will only send notifications to the Lambda function when an object is created within that specific virtual folder. Combining this with the `s3:ObjectCreated:*` event type ensures that the Lambda function is invoked solely for new object uploads in the designated path, optimizing resource utilization and minimizing unnecessary Lambda invocations and associated costs.

Why this answer

S3 event notifications support prefix filtering, which allows you to specify a key prefix (e.g., 'uploads/') so that only object creation events in that subfolder trigger the Lambda function. By setting the event type to 's3:ObjectCreated:*', the function responds to all object creation operations (PUT, POST, Copy, etc.) within the filtered path, meeting the requirement precisely without unnecessary invocations.

Exam trap

The trap here is that candidates might think filtering inside the Lambda function is acceptable (Option B), but AWS best practice and the exam emphasize configuring filtering at the event source to minimize invocations and follow the principle of least privilege for triggers.

How to eliminate wrong answers

Option B is wrong because filtering on the prefix inside the Lambda function would still cause the function to be invoked for every object created in the bucket, leading to unnecessary executions and increased costs; S3 event notifications support prefix filtering natively, so this should be configured at the event source level. Option C is wrong because S3 event notifications do not support filtering by object tags; tag-based filtering is not a feature of S3 event notifications, and tags are not evaluated during event generation. Option D is wrong because AWS CloudTrail is not designed for real-time event-driven triggers; it logs API calls with a delay and is intended for auditing, not for invoking Lambda functions in response to S3 object creation events.

42
MCQmedium

A developer attaches the IAM policy shown to a user. The user attempts to upload an object to example-bucket using the AWS CLI with the command: `aws s3 cp file.txt s3://example-bucket/`. The upload fails. What is the MOST likely reason?

A.The user does not have permission to perform s3:PutObject on the bucket.
B.The bucket policy overrides the IAM policy and denies the request.
C.The resource ARN does not include the bucket itself.
D.The user did not specify server-side encryption in the request.
AnswerD

The IAM policy includes a `Condition` requiring `s3:x-amz-server-side-encryption` to be `AES256`. This means any `s3:PutObject` request must explicitly include the `x-amz-server-side-encryption` header with the exact value `AES256`. If the user's request omits this specific header or provides a different encryption method, the condition will not be met, and the action will be implicitly denied, causing the upload to fail.

Why this answer

The IAM policy shown (not provided in the question but implied by the context) likely includes a condition that requires server-side encryption (e.g., `s3:x-amz-server-side-encryption: AES256`). The `aws s3 cp` command by default does not set the `--sse` flag, so the request lacks the required encryption header, causing S3 to deny the upload with an AccessDenied error.

Exam trap

The trap here is that candidates often assume an upload failure is due to missing `s3:PutObject` permission, overlooking that S3 condition keys (like encryption requirements) can silently deny requests even when the base action is allowed.

How to eliminate wrong answers

Option A is wrong because the IAM policy likely grants `s3:PutObject` on the bucket (the policy is not shown but the question implies it exists), so the failure is not due to missing PutObject permission. Option B is wrong because bucket policies and IAM policies are evaluated together; unless an explicit Deny exists, the effective permission is the union of allows, and the question does not indicate a bucket policy. Option C is wrong because the resource ARN `arn:aws:s3:::example-bucket/*` correctly covers objects within the bucket, and the `s3:PutObject` action operates on objects, not the bucket itself.

43
MCQeasy

A developer is building a RESTful API that allows clients to query a database and retrieve results. The backend logic is implemented in AWS Lambda, which queries an Amazon DynamoDB table. The developer wants to expose the API over HTTPS and manage authentication and throttling. Which AWS service should the developer use to create and manage the API endpoints?

A.Application Load Balancer
B.Amazon API Gateway
C.AWS CloudFront
D.Amazon S3
AnswerB

Amazon API Gateway is a fully managed service specifically designed for creating, publishing, maintaining, monitoring, and securing REST, HTTP, and WebSocket APIs at any scale. It acts as a secure 'front door' for applications to access data, business logic, or functionality from backend services like AWS Lambda or DynamoDB. Key features include request/response transformation, authentication (e.g., API keys, IAM, Cognito), throttling, caching, and custom domain support, making it ideal for exposing a database query API.

Why this answer

Amazon API Gateway is the correct choice because it is a fully managed service that enables developers to create, publish, maintain, monitor, and secure RESTful APIs at any scale. It directly supports HTTPS endpoints, integrates natively with AWS Lambda for backend logic, and provides built-in features for authentication (e.g., IAM, Cognito, Lambda authorizers) and throttling (usage plans and rate limits). This makes it the ideal service for exposing a Lambda-backed DynamoDB query as a secure, managed API.

Exam trap

The trap here is that candidates may confuse an Application Load Balancer with API Gateway because both can invoke Lambda functions, but ALB lacks API management features like authentication, throttling, and API key validation, which are explicitly required in the question.

How to eliminate wrong answers

Option A is wrong because an Application Load Balancer operates at Layer 7 of the OSI model and distributes traffic to targets like Lambda functions, but it does not provide API management features such as authentication, throttling, or API key validation; it is designed for load balancing, not for creating and managing RESTful API endpoints. Option C is wrong because AWS CloudFront is a content delivery network (CDN) that caches and accelerates content delivery, but it does not natively create API endpoints or manage authentication and throttling for a RESTful API; it can be placed in front of API Gateway but is not a substitute for it. Option D is wrong because Amazon S3 is an object storage service that can host static websites and serve content over HTTPS, but it cannot execute backend logic like querying a DynamoDB table, nor does it provide authentication or throttling for API requests; it is not designed for dynamic API endpoints.

44
MCQeasy

An organization uses AWS CodeCommit for source control and AWS CodeBuild for building a Java application. The build process needs to run integration tests that require a MySQL database. The team wants to ensure the database is provisioned only during the build and cleaned up afterward to minimize costs. What is the most efficient solution?

A.Provision a small RDS MySQL instance and keep it running for the build process.
B.Use AWS CloudFormation to create an RDS instance at the start of the build and delete it at the end.
C.Use a Docker container running MySQL within the CodeBuild environment.
D.Use Amazon DynamoDB as a substitute for MySQL for the integration tests.
AnswerC

Using a Docker container running MySQL directly within the CodeBuild environment is an efficient and cost-effective solution. CodeBuild supports running services as Docker containers alongside the build environment, allowing MySQL to be spun up quickly and ephemerally for each build. This approach ensures a clean database instance for every integration test run, providing isolation and repeatability without incurring persistent costs for an always-on database.

Why this answer

Running MySQL inside a Docker container within the CodeBuild environment is the most efficient solution because the database is ephemeral, starts and stops with the build, and incurs no persistent infrastructure cost. CodeBuild supports Docker via the privileged mode setting, and the container can be started in the buildspec's pre_build phase and torn down automatically when the build finishes. This satisfies the requirement to provision only during the build and clean up afterward.

Exam trap

DVA-C02 often tests the misconception that CloudFormation-provisioned RDS is the 'proper' way to get a temporary database — candidates overlook that Docker-in-CodeBuild is faster, cheaper, and truly ephemeral.

How to eliminate wrong answers

Option A is wrong because keeping an RDS MySQL instance running continuously incurs ongoing cost and violates the requirement to provision only during the build. Option B is wrong because creating and deleting an RDS instance via CloudFormation at the start and end of each build is slow (RDS provisioning takes several minutes), error-prone, and still incurs cost during the build window. Option D is wrong because DynamoDB is a NoSQL database and is not compatible with MySQL integration tests that rely on SQL syntax, drivers, and schema.

45
MCQmedium

A company uses Amazon API Gateway to expose a REST API backed by AWS Lambda. The API is experiencing high latency. The developer suspects cold starts are contributing to the latency. Which action would be MOST effective in reducing cold start latency?

A.Increase the memory allocation of the Lambda function.
B.Place the Lambda function in a VPC to improve network latency.
C.Enable Lambda@Edge to cache responses.
D.Increase the function timeout to 15 minutes.
AnswerA

Increasing the memory allocation for a Lambda function directly correlates with an increase in allocated CPU power. AWS Lambda provisions CPU cycles proportionally to the memory configured for the function. More CPU resources allow the function's execution environment to initialize faster, load dependencies more quickly, and execute the handler code more efficiently during a cold start, thereby reducing the overall latency experienced by the user.

Why this answer

Increasing the memory allocation of a Lambda function directly correlates to allocating more CPU power, which reduces the initialization time during a cold start. AWS Lambda provisions CPU proportionally to the configured memory, so a higher memory setting speeds up the runtime environment setup and code loading, thereby lowering cold start latency.

Exam trap

The trap here is that candidates often confuse increasing timeout with improving performance, but timeout only affects how long a function can run, not how quickly it starts.

How to eliminate wrong answers

Option B is wrong because placing a Lambda function in a VPC adds an Elastic Network Interface (ENI) setup step during cold starts, which actually increases latency, not reduces it. Option C is wrong because Lambda@Edge is designed for content delivery and caching at CloudFront edge locations, not for reducing cold start latency of an API Gateway backend Lambda function. Option D is wrong because increasing the function timeout to 15 minutes does not affect the initialization phase of a cold start; it only allows the function to run longer, which does not address the latency issue.

46
MCQeasy

A company is using AWS CodePipeline to automate deployments. The pipeline has a source stage that retrieves code from Amazon S3, a build stage using AWS CodeBuild, and a deploy stage using AWS CodeDeploy. The build stage is failing intermittently with errors related to missing dependencies. What should a developer do to ensure the build environment has all required dependencies?

A.Configure environment variables in CodePipeline to set dependency paths.
B.Manually install dependencies on the CodeBuild build server each time.
C.Use AWS CodeCommit as the source repository instead of S3.
D.Create a custom buildspec.yml file in the source code that installs the dependencies in the install phase.
AnswerD

Creating a custom `buildspec.yml` file in the source code is the standard and most effective method for automating dependency installation within AWS CodeBuild. By defining commands in the `install` phase of the `buildspec.yml` (e.g., `npm install`, `pip install`), CodeBuild automatically executes these steps every time the project is built. This ensures that all necessary dependencies are consistently fetched and installed, making the build process reproducible, reliable, and fully integrated with the source code version control.

Why this answer

The buildspec.yml file defines the build phases for AWS CodeBuild, including the install phase where you can specify commands to install dependencies (e.g., using package managers like pip, npm, or apt-get). By placing this file in the source code, the build environment automatically executes these commands on every build, ensuring all required dependencies are present and consistent across runs, which resolves intermittent failures caused by missing dependencies.

Exam trap

The trap here is that candidates may think environment variables (Option A) can solve dependency issues, but they confuse configuration with actual installation, or they assume changing the source repository (Option C) will somehow fix build failures, when the real solution lies in defining the build process within the source code itself.

How to eliminate wrong answers

Option A is wrong because environment variables in CodePipeline can set paths or configuration values but cannot install or fetch missing dependencies; they only influence runtime behavior of existing tools. Option B is wrong because manually installing dependencies on the CodeBuild build server is impractical and defeats automation—CodeBuild uses ephemeral, disposable build environments that are recreated for each build, so manual changes are lost. Option C is wrong because switching to CodeCommit as the source repository does not address missing dependencies; the source type (S3 vs.

CodeCommit) has no impact on dependency installation in the build stage.

47
MCQhard

A developer is running a Lambda function that uses the 'requests' library. The error shown in the exhibit occurs when invoking the function. Which step should the developer take to fix this?

A.Change the Lambda runtime to Python 3.9 which includes requests
B.Package the 'requests' library with the Lambda deployment package
C.Use the 'urllib' library instead of 'requests'
D.Install the 'requests' library using pip in the Lambda console
AnswerB

To successfully use the `requests` library in an AWS Lambda function, it must be included as part of the deployment package. This typically involves installing `requests` and its dependencies into a local directory, then zipping that directory along with the function's handler code. Alternatively, for shared dependencies across multiple functions, a Lambda Layer can be created and attached, which is a best practice for managing common libraries efficiently.

Why this answer

The 'requests' library is not included in the AWS Lambda Python runtime by default. To use it, the developer must package the library as a dependency layer or include it in the deployment package. Option B correctly identifies this approach, ensuring the library is available at runtime.

Exam trap

The trap here is that candidates assume AWS Lambda runtimes include popular third-party libraries like 'requests', but in reality only the standard library is provided, so dependencies must be bundled manually.

How to eliminate wrong answers

Option A is wrong because no AWS Lambda Python runtime (including Python 3.9) includes the 'requests' library by default; it must be bundled manually. Option C is wrong because switching to 'urllib' is a workaround, not a fix for the missing dependency, and may require significant code changes. Option D is wrong because the Lambda console does not support installing libraries via pip; dependencies must be packaged locally or via a Lambda layer.

48
MCQhard

Refer to the exhibit. An IAM policy is attached to an IAM user. The user tries to upload an object to s3://my-bucket/confidential/report.pdf. What is the outcome?

A.The upload succeeds because the Allow statement grants s3:PutObject on the bucket.
B.The upload fails because there is no Allow statement for the confidential prefix.
C.The upload fails because the Deny statement explicitly denies access to the confidential prefix.
D.The upload fails because the policy is malformed.
AnswerC

The upload fails precisely because the IAM policy contains an explicit Deny statement for the s3:PutObject action on resources within the confidential prefix. In AWS IAM policy evaluation, an explicit Deny always overrides any Allow statements that might otherwise grant access, regardless of their scope or specificity. This strict precedence ensures that sensitive operations or resources can be absolutely protected.

Why this answer

The IAM policy includes an explicit Deny statement for s3:PutObject on the `confidential` prefix, which overrides any Allow statements. AWS IAM evaluates policies with explicit Denies taking precedence over Allows, so the upload to `s3://my-bucket/confidential/report.pdf` is blocked regardless of the Allow statement on the bucket.

Exam trap

The trap here is that candidates often assume an Allow statement on the bucket is sufficient for all objects, forgetting that an explicit Deny on a specific prefix takes precedence and blocks the action.

How to eliminate wrong answers

Option A is wrong because while the Allow statement grants s3:PutObject on the bucket, the explicit Deny statement for the `confidential` prefix overrides it, causing the upload to fail. Option B is wrong because the failure is not due to a missing Allow statement; the Allow statement exists on the bucket, but the Deny statement explicitly blocks the action on the `confidential` prefix. Option D is wrong because the policy is not malformed; it is syntactically valid and follows IAM policy structure.

49
MCQmedium

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application stores session state in an S3 bucket. Users report that after logging in, they are sometimes redirected to the login page again on subsequent requests. What is the MOST likely cause?

A.S3 is not a suitable store for session state due to its higher latency compared to in-memory stores like ElastiCache or DynamoDB.
B.The EC2 instances do not have internet access to reach S3.
C.The ALB does not have sticky sessions enabled.
D.The application is not scaling properly, causing session loss.
AnswerA

Amazon S3, while highly durable and scalable, is an object storage service optimized for throughput of large objects and cost-effectiveness, not for low-latency, high-frequency access to small, frequently changing data like session state. Its typical latency, even with strong consistency, is significantly higher than in-memory caches like ElastiCache (Redis/Memcached) or specialized NoSQL databases like DynamoDB. This higher latency can cause the application to time out when attempting to retrieve session data, leading to the perception of a lost session and subsequent redirection to the login page.

Why this answer

Amazon S3 now provides strong read-after-write consistency, so eventual consistency is not the cause. However, S3's higher latency compared to in-memory stores like ElastiCache or DynamoDB makes it unsuitable for session management, which requires fast, frequent reads and writes. The higher latency can cause delays in session retrieval, leading to timeouts and the login page being displayed again.

Exam trap

Candidates may incorrectly attribute the problem to S3's eventual consistency, which was fixed. The real issue is S3's higher latency relative to in-memory services, making it a poor choice for session state.

How to eliminate wrong answers

Option B is wrong because EC2 instances in a VPC can access S3 via a VPC endpoint or NAT gateway without requiring internet access; the lack of internet access alone would not cause intermittent session loss. Option C is wrong because sticky sessions (session affinity) are used to route requests to the same EC2 instance, but the session state is stored in S3, not on the instance, so sticky sessions are irrelevant to session persistence. Option D is wrong because scaling issues would cause all sessions to be lost or new instances to be unable to serve existing sessions, not intermittent redirects to the login page; the described behavior points to a data consistency problem, not capacity.

50
MCQmedium

A company runs a microservices architecture on Amazon ECS with Fargate. The application experiences intermittent high latency. The operations team wants to trace requests across services and identify bottlenecks. Which AWS service should be used?

A.VPC Flow Logs
B.Amazon CloudWatch Logs
C.AWS X-Ray
D.Amazon CloudWatch Metrics
AnswerC

AWS X-Ray is purpose-built for end-to-end tracing and analysis of requests as they flow through distributed applications, including those running on Amazon ECS microservices. It collects data about requests, responses, and calls to downstream services, providing a visual service map, detailed trace data, and latency breakdowns for each segment. This enables developers to precisely identify performance bottlenecks, errors, and the full execution path of individual requests across complex architectures.

Why this answer

AWS X-Ray is the correct service because it provides end-to-end tracing of requests as they travel through microservices, capturing latency at each hop. It generates a service map that visualizes the flow and pinpoints bottlenecks, which is exactly what the operations team needs for a distributed application on ECS Fargate.

Exam trap

The trap here is that candidates confuse CloudWatch Logs (which shows logs) or Metrics (which shows aggregates) with the distributed tracing capability that X-Ray uniquely provides for microservices architectures.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture IP traffic metadata (source/destination, ports, protocols) but do not trace application-level requests or measure service latency. Option B is wrong because Amazon CloudWatch Logs aggregates log data but lacks the distributed tracing capability to follow a single request across multiple services and identify per-service latency. Option D is wrong because Amazon CloudWatch Metrics provides aggregated performance data (e.g., CPU, memory) but cannot trace individual request paths or pinpoint which specific service call caused the latency.

51
Multi-Selectmedium

Which TWO actions should a developer take to improve the security of an AWS Lambda function that processes sensitive data?

Select 2 answers
A.Use a dead-letter queue (DLQ) for failed invocations
B.Encrypt environment variables using AWS KMS
C.Grant the Lambda function full access to all S3 buckets
D.Run the Lambda function inside a VPC
E.Store secrets in the Lambda function code
AnswersB, D

Encrypting environment variables with AWS Key Management Service (KMS) ensures that sensitive data, such as API keys or database credentials, is protected when stored at rest within the Lambda service configuration. This prevents unauthorized access to these secrets if the Lambda configuration is compromised, as the data remains encrypted until the function is invoked and decrypted by the Lambda runtime using the specified KMS key.

Why this answer

Encrypting environment variables with AWS KMS ensures that sensitive data, such as database credentials or API keys, is protected at rest and in transit during function deployment. This is a critical security best practice because environment variables are visible in plaintext in the Lambda console and API responses unless encrypted. KMS provides envelope encryption, where a customer master key (CMK) encrypts the data key that encrypts the environment variables, giving you full control over access and key rotation.

Exam trap

The trap here is that candidates may think a DLQ (Option A) improves security by handling failures, but it is a reliability mechanism, not a security control, and they may overlook that running a Lambda in a VPC (Option D) is a security measure to isolate network traffic, even though it is not directly about encrypting data.

52
MCQmedium

Refer to the exhibit. A developer invoked a Lambda function and received the response shown. What does the response indicate?

A.The function was not invoked due to a permissions error.
B.The function executed successfully but did not return any logs.
C.The invocation timed out.
D.The function was invoked but returned an error.
AnswerD

The presence of the `FunctionError` header in the Lambda invocation response explicitly indicates that the function code was successfully invoked by the Lambda service, but encountered an unhandled error during its execution. This error could be an exception thrown by the function code that was not caught, or a runtime error that prevented successful completion. The Lambda service captures this and signals it via the `FunctionError` header, even if the HTTP status code is 200.

Why this answer

The response includes a 'FunctionError' field with value 'Unhandled' and an 'error' object, indicating that the Lambda function was invoked successfully (StatusCode 200) but the function itself encountered an error during execution. Option A is incorrect because a permissions error would result in a 4xx or 5xx StatusCode, not 200. Option B is incorrect because the function did not execute successfully—it returned an error.

Option C is incorrect because a timeout would typically produce a 'null' FunctionError or a specific timeout error, not an explicit error object. Option D is correct: the function was invoked, but it returned an error.

53
Multi-Selecthard

Which TWO of the following are required to enable cross-origin resource sharing (CORS) for an API hosted on Amazon API Gateway? (Choose two.)

Select 2 answers
A.Modify the Lambda function to return CORS headers in the response
B.Configure Amazon CloudFront to add CORS headers
C.Add an OPTIONS method to the API Gateway resource and configure it to return the required CORS headers
D.Configure an S3 bucket CORS policy
E.Enable CORS on the API Gateway resource and deploy the API
AnswersC, E

Browsers perform an HTTP OPTIONS 'preflight' request before certain cross-origin requests (e.g., those using non-simple methods or custom headers). To enable CORS, API Gateway must explicitly respond to these OPTIONS requests with the appropriate `Access-Control-Allow-*` headers. Manually adding an OPTIONS method to the resource and configuring its integration response to return these specific headers is a fundamental and correct way to satisfy the CORS preflight requirement.

Why this answer

CORS requires a preflight OPTIONS request to determine if the actual request is safe to send. By adding an OPTIONS method to the API Gateway resource and configuring it to return the required CORS headers (such as Access-Control-Allow-Origin, Access-Control-Allow-Methods, and Access-Control-Allow-Headers), the API can respond to the browser's preflight request and enable cross-origin requests.

Exam trap

The trap here is that candidates often think modifying the Lambda function to return CORS headers is sufficient, but they forget that the browser's preflight OPTIONS request must be handled separately, and without an OPTIONS method on the API Gateway resource, the preflight will fail.

54
Multi-Selectmedium

A company is using AWS CodePipeline to automate deployments. The pipeline has a source stage that retrieves code from an S3 bucket, a build stage using CodeBuild, and a deploy stage using CodeDeploy. The build stage sometimes fails due to intermittent network issues. Which TWO actions would make the pipeline more resilient to such failures?

Select 1 answer
A.Enable retry on the build stage to automatically attempt the build again on failure.
B.Store build artifacts in a different S3 bucket.
C.Add a manual approval stage before the build stage.
D.Configure the build stage to run multiple build actions in parallel.
E.Use a different source repository, such as CodeCommit.
AnswersA

CodePipeline supports automatic retry on failed actions. Enabling retry on the build stage automatically re-runs the build if it fails due to transient network issues, improving resilience.

Why this answer

Option A is correct because CodePipeline supports automatic stage retry, which re-runs the failed build stage (including its CodeBuild action) after an intermittent network failure, allowing transient issues to resolve without manual intervention. Option D is incorrect because CodePipeline does not allow a stage to succeed when only one of several parallel actions succeeds; all actions in a stage must succeed for the stage to succeed, so running multiple build actions in parallel does not provide redundancy against transient failures and only adds complexity. Option B is incorrect because changing the artifact S3 bucket does not address intermittent network failures during the build.

Option C is incorrect because a manual approval stage only pauses the pipeline for human review and does not automatically recover from network-related build failures. Option E is incorrect because switching the source repository to CodeCommit does not make the CodeBuild stage resilient to intermittent network issues.

Exam trap

A common mistake is to assume that running multiple actions in parallel provides redundancy. In CodePipeline, all actions in a stage must succeed for the stage to succeed, so parallel execution does not make the pipeline resilient to a single action's transient failure. Retry logic is the correct mechanism for handling intermittent failures.

55
Multi-Selectmedium

A developer is deploying a new version of an AWS Lambda function using the AWS CLI. The function is currently active and handling traffic. The developer wants to gradually shift traffic to the new version and rollback if errors increase. Which TWO actions should the developer take? (Choose TWO.)

Select 2 answers
A.Configure the alias to route a percentage of traffic to the new version and the rest to the current version.
B.Create a new version of the Lambda function.
C.Invoke the Lambda function with the new version using the AWS SDK.
D.Update the alias to route 100% of traffic to the new version.
E.Use AWS CodeDeploy to create a deployment group for the Lambda function.
AnswersA, B

This is a core capability of Lambda aliases, allowing for controlled, gradual rollouts of new function versions. By configuring a "weighted alias," a developer can specify a percentage of invocations to be directed to the new version while the remaining traffic continues to hit the stable, current version. This enables canary deployments, where the new version can be monitored for errors or performance regressions with minimal impact before a full rollout.

Why this answer

Lambda aliases support weighted routing, allowing you to specify a percentage of traffic to send to a new version while the remainder goes to the current version. This enables canary deployments where you can monitor error rates and rollback by adjusting the weights without redeploying.

Exam trap

The trap here is that candidates often think they must use an external service like CodeDeploy (Option E) for gradual traffic shifting, but Lambda aliases natively support weighted routing without additional services.

56
MCQmedium

A developer needs to securely store database credentials for a Lambda function that accesses an Amazon RDS instance. The credentials must be automatically rotated every 30 days. Which AWS service should be used?

A.AWS IAM Roles for Lambda
B.AWS Secrets Manager
C.AWS Key Management Service (KMS)
D.AWS Systems Manager Parameter Store
AnswerB

AWS Secrets Manager is purpose-built for securely storing, managing, and retrieving sensitive information such as database credentials, API keys, and other secrets. It offers critical security features like automatic rotation of secrets, which is essential for enhancing security posture and reducing the risk of compromise. Furthermore, Secrets Manager provides fine-grained access control and integrates seamlessly with various AWS services and databases for streamlined secret management.

Why this answer

AWS Secrets Manager is the correct choice because it is specifically designed to securely store, manage, and automatically rotate database credentials for services like Amazon RDS. It supports built-in rotation with a configurable schedule (e.g., every 30 days) using a Lambda rotation function, and it integrates directly with RDS to update credentials without manual intervention. This meets the requirement for automatic rotation and secure storage.

Exam trap

Candidates often choose Parameter Store because it is cheaper and can store secrets, but it lacks native rotation scheduling for RDS credentials.

How to eliminate wrong answers

Option A is wrong because AWS IAM Roles for Lambda provide temporary credentials for API calls but cannot store or rotate database credentials; they are used for granting permissions to AWS services, not for managing secrets like usernames and passwords. Option C is wrong because AWS Key Management Service (KMS) is a key management service for encrypting data at rest and in transit, but it does not store secrets or provide automatic rotation of database credentials; it is used as an encryption key source, not a secret store. Option D is wrong because AWS Systems Manager Parameter Store can store secrets securely, but it lacks built-in automatic rotation capabilities for database credentials; while it can be integrated with custom rotation logic, it does not natively support scheduled rotation like Secrets Manager does.

57
MCQhard

A developer is building a serverless application that processes images uploaded to an S3 bucket. The bucket triggers a Lambda function that creates a thumbnail and stores it in another S3 bucket. The developer notices that the Lambda function is invoked multiple times for the same object, causing duplicate thumbnails. What is the MOST likely cause?

A.S3 event notifications are eventually consistent and may deliver duplicates.
B.The Lambda function is configured with a DLQ that causes retries.
C.The Lambda function is idempotent and should handle duplicates.
D.The S3 bucket has multiple event notifications that trigger the same Lambda function.
AnswerA

S3 event notifications are designed for at-least-once delivery, meaning duplicates are possible under rare circumstances like network issues or internal retries within AWS. However, the 'eventually consistent' nature of S3 object storage itself does not directly cause duplicate notification deliveries in the way this option implies. While S3 consistency models affect read-after-write behavior, they are not the primary or most common reason for receiving multiple identical event notifications for a single S3 action.

Why this answer

Amazon S3 event notifications are designed to provide at-least-once delivery. This means that while most events are delivered exactly once, duplicate event notifications can occasionally occur. To handle this, the Lambda function should be designed to be idempotent, ensuring that processing the same event multiple times does not cause unintended side effects (like duplicate thumbnails).

Exam trap

Candidates often assume that S3 event notifications guarantee exactly-once delivery, or they confuse S3's data consistency model (which is now strongly consistent for read-after-write) with its event delivery model (which is at-least-once).

How to eliminate wrong answers

Option A is wrong because S3 event notifications are designed to be delivered at least once, but they are not eventually consistent for new object creations; duplicates from S3 itself are rare and typically caused by retries due to failures, not by eventual consistency. Option B is wrong because a Dead Letter Queue (DLQ) does not cause retries; it captures events that have exhausted their retry attempts, and retries are controlled by the Lambda function's asynchronous invocation retry policy (up to 2 additional attempts), not by the DLQ. Option C is wrong because while idempotency is a best practice to handle duplicates, it is not the cause of the duplicates; the question asks for the most likely cause, not a solution.

58
Multi-Selectmedium

Which THREE actions can be performed using AWS Lambda and Amazon S3 event notifications? (Choose three.)

Select 3 answers
A.Resize an image when a new image is uploaded to an S3 bucket.
B.Generate a pre-signed URL for an object.
C.Scan an uploaded file for viruses.
D.Enable versioning on the S3 bucket.
E.Transcode a video when a new video file is created.
AnswersA, C, E

When an object is uploaded to an S3 bucket, S3 can publish an event notification (e.g., s3:ObjectCreated:Put) to an AWS Lambda function. The Lambda function can then retrieve the newly uploaded image, perform image manipulation like resizing using libraries (e.g., Pillow in Python), and save the processed image back to S3, potentially in a different bucket or with a different key. This is a classic serverless image processing pattern.

Why this answer

AWS Lambda can be triggered by S3 event notifications for object creation events. When a new image is uploaded to an S3 bucket, the event notification invokes a Lambda function that can process the image, such as resizing it using libraries like Pillow or Sharp, and save the resized version back to S3.

Exam trap

AWS often tests the distinction between actions that can be automated via S3 event notifications triggering Lambda (asynchronous processing of existing objects) versus actions that require direct SDK calls or bucket-level configuration changes.

59
MCQeasy

A developer wants to deploy a containerized application on AWS. The application requires persistent storage that can be accessed by multiple containers running on different EC2 instances. Which AWS service should the developer use?

A.Amazon Elastic File System (EFS)
B.Amazon Elastic Block Store (EBS)
C.Amazon Simple Storage Service (S3)
D.Amazon DynamoDB
AnswerA

Amazon Elastic File System (EFS) provides a scalable, fully managed, shared file system that can be mounted by multiple container instances (e.g., running on EC2 or Fargate) simultaneously. This allows containerized applications to access common data, such as configuration files, user-generated content, or persistent state, ensuring data consistency and availability across all containers. Its POSIX compliance makes it suitable for traditional file system operations required by many applications.

Why this answer

Amazon EFS provides a fully managed, scalable, and elastic NFS file system that can be mounted concurrently on multiple EC2 instances across different Availability Zones. This makes it the ideal choice for a containerized application requiring shared persistent storage accessible by multiple containers running on different instances, as it supports the NFSv4.1 and NFSv4.0 protocols for simultaneous access.

Exam trap

The trap here is that candidates often confuse EBS with EFS, assuming EBS supports multi-instance access by default, but EBS volumes are single-instance attached unless using the limited multi-attach feature, which is not designed for general-purpose shared file system use.

How to eliminate wrong answers

Option B (Amazon EBS) is wrong because EBS volumes are block-level storage devices that can only be attached to a single EC2 instance at a time (except for specific multi-attach EBS configurations, which are limited to io1/io2 volumes and a small number of instances, not suitable for general multi-container access across different instances). Option C (Amazon S3) is wrong because S3 is an object storage service accessed via HTTP/HTTPS APIs, not a file system mountable via NFS, and it does not provide low-latency file-level locking or POSIX-like semantics required for shared file system access by containers. Option D (Amazon DynamoDB) is wrong because DynamoDB is a NoSQL key-value and document database, not a file storage service, and it is designed for structured data access patterns, not for storing and sharing container files or directories.

60
MCQhard

A company has a monolithic application running on an EC2 instance that needs to be migrated to a microservices architecture on AWS. The development team wants to use AWS services to handle service discovery, configuration management, and secrets management. Which combination of AWS services should the team use?

A.Use Amazon ECS Service Discovery for service discovery, AWS Config for configuration, and AWS Systems Manager Parameter Store for secrets.
B.Use AWS Cloud Map for service discovery, AWS AppConfig for configuration, and AWS Secrets Manager for secrets.
C.Use AWS Cloud Map for service discovery, AWS Systems Manager Parameter Store for configuration, and AWS Secrets Manager for secrets.
D.Use AWS Service Discovery for service discovery, EC2 Image Builder for configuration, and AWS Key Management Service (KMS) for secrets.
AnswerB

This option correctly identifies the purpose-built AWS services for each requirement. AWS Cloud Map provides a unified service registry for all application resources, enabling dynamic discovery for EC2-based applications through DNS or API calls. AWS AppConfig is specifically designed for safe, controlled deployment and management of application configurations, including validation and rollback capabilities. AWS Secrets Manager is the most secure and feature-rich service for storing, rotating, and managing sensitive credentials and API keys.

Why this answer

AWS Cloud Map provides service discovery for microservices by registering service instances and enabling DNS-based or API-based resolution. AWS AppConfig manages application configuration with validation and controlled rollouts, and AWS Secrets Manager handles secrets management with automatic rotation and fine-grained access control. Together, these services meet the specific needs of service discovery, configuration management, and secrets management in a microservices architecture.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store (which can store secrets but lacks automatic rotation and advanced access control) with AWS Secrets Manager, or mistakenly think AWS Config is suitable for application configuration management when it is actually for resource compliance and auditing.

How to eliminate wrong answers

Option A is wrong because AWS Config is designed for resource compliance and auditing, not for managing application configuration; it cannot push configuration updates or handle feature flags. Option C is wrong because AWS Systems Manager Parameter Store is a general-purpose parameter store that lacks built-in secrets rotation and advanced access control compared to Secrets Manager, making it less suitable for secrets management in a microservices context. Option D is wrong because 'AWS Service Discovery' is not a standalone AWS service (the correct service is AWS Cloud Map), EC2 Image Builder is for creating machine images, not configuration management, and AWS KMS is a key management service, not a secrets management service.

61
MCQeasy

A developer is building a microservices application that processes event messages from multiple sources. The application requires at-least-once delivery, but message ordering is not important. Which Amazon SQS queue type should the developer use?

A.Standard queue
B.FIFO queue
C.Dead-letter queue
D.Delay queue
AnswerA

Standard queues are the default SQS queue type, designed for high throughput and best-effort ordering. They guarantee at-least-once message delivery, meaning a message might be delivered more than once, which requires consumers to be idempotent. This queue type is ideal for microservices where strict message ordering is not critical, and the application can handle occasional duplicates or out-of-order processing efficiently.

Why this answer

Amazon SQS Standard queues provide at-least-once delivery and best-effort ordering, making them ideal for microservices that can tolerate duplicate messages and do not require strict message sequencing. Since the application processes events from multiple sources and message ordering is not important, a Standard queue meets the requirements without the throughput limitations of FIFO queues.

Exam trap

The trap here is that candidates often confuse the 'at-least-once' delivery requirement with the need for ordering, leading them to choose FIFO queues, but the question explicitly states ordering is not important, making Standard queues the correct and more performant choice.

How to eliminate wrong answers

Option B is wrong because FIFO queues guarantee exactly-once processing and strict message ordering, which are unnecessary here and would impose a throughput limit of 3,000 transactions per second (with batching) or 300 without, adding cost and complexity. Option C is wrong because a dead-letter queue is not a primary queue type for receiving messages; it is a secondary queue used to capture messages that fail processing after a specified number of receive attempts. Option D is wrong because a delay queue is not a distinct queue type but a feature of Standard or FIFO queues that introduces an initial message delay (up to 15 minutes), which does not address the core requirement of at-least-once delivery.

62
MCQhard

A developer is using AWS CodePipeline to deploy a serverless application. The pipeline has a source stage (CodeCommit), a build stage (CodeBuild), and a deploy stage (CloudFormation). The developer wants to automatically roll back the deployment if the CloudFormation stack update fails. Which configuration should be used?

A.Add a stack policy to the CloudFormation stack to prevent updates.
B.Set the deployment to use AWS CodeDeploy and enable rollback.
C.Configure a manual approval action in the pipeline to trigger a rollback.
D.Configure the CloudFormation stack to roll back on failure using the RollbackConfiguration.
AnswerD

Configuring the CloudFormation stack with a `RollbackConfiguration` is the correct and most effective method for automatically rolling back a failed stack update. This feature allows you to specify CloudWatch alarms that CloudFormation monitors during and after a stack update. If any specified alarm enters an `ALARM` state within a defined monitoring period, CloudFormation will automatically initiate a rollback to the stack's previous stable state, ensuring service stability.

Why this answer

CloudFormation natively supports automatic rollback on stack update failure through the `RollbackConfiguration` property. When a stack update fails, CloudFormation can automatically revert to the last known good state, which is exactly what the developer needs for a serverless deployment pipeline. This configuration can be set in the CloudFormation template or passed as a parameter during the deploy action in CodePipeline.

Exam trap

The trap here is that candidates may confuse CloudFormation's built-in rollback capability with external services like CodeDeploy, or assume that manual approval is required for rollback, when in fact CloudFormation can handle it automatically via `RollbackConfiguration`.

How to eliminate wrong answers

Option A is wrong because a stack policy prevents updates to specific resources but does not provide rollback on failure; it would block the deployment entirely. Option B is wrong because CodeDeploy is used for deploying applications to EC2, Lambda, or ECS, not for CloudFormation stack updates; it cannot manage CloudFormation rollbacks. Option C is wrong because a manual approval action pauses the pipeline for human review but does not automatically trigger a rollback; it requires manual intervention to initiate a rollback, which contradicts the requirement for automatic rollback.

63
MCQhard

A developer creates the CloudFormation stack with the template above. After the stack is created, messages that are not processed after 5 receives are moved to the DLQ. However, the developer notices that the RedrivePolicy references a queue ARN that is hardcoded. What is the best practice to avoid this hardcoded ARN?

A.Use Ref to reference the DLQ's QueueName and construct the ARN.
B.Use Fn::Sub to substitute the queue name into a hardcoded ARN template.
C.Use Fn::ImportValue to import the DLQ ARN from another stack.
D.Use Fn::GetAtt with "Arn" attribute on the DLQ resource.
AnswerD

Fn::GetAtt is the correct and most robust intrinsic function for retrieving a specific attribute from a resource defined within the same CloudFormation template. For an AWS::SQS::Queue resource, the Arn attribute directly provides the complete Amazon Resource Name (ARN) of the queue. This approach dynamically fetches the fully qualified ARN, eliminating the need for hardcoding account IDs, regions, or manual string construction, ensuring accuracy and portability across environments.

Why this answer

`Fn::GetAtt` with the `Arn` attribute retrieves the actual Amazon Resource Name (ARN) of the Dead Letter Queue (DLQ) resource dynamically at stack creation time. This avoids hardcoding the ARN, making the template portable across accounts and regions. The RedrivePolicy property requires the full ARN of the DLQ, and `Fn::GetAtt` is the intrinsic function designed to return resource attributes like ARN.

Exam trap

The trap here is that candidates often confuse `Ref` (which returns the QueueName or Queue URL) with `Fn::GetAtt` (which returns the ARN), leading them to choose Option A or attempt manual ARN construction with `Fn::Sub`.

How to eliminate wrong answers

Option A is wrong because `Ref` on an SQS queue returns the QueueName (or Queue URL in some contexts), not the ARN, and constructing the ARN manually is error-prone and not a best practice. Option B is wrong because `Fn::Sub` with a hardcoded ARN template still contains a static ARN pattern (e.g., `arn:aws:sqs:${AWS::Region}:${AWS::AccountId}:queue-name`), which is fragile if the queue name changes or if the stack is deployed to a different partition (e.g., GovCloud). Option C is wrong because `Fn::ImportValue` is used to import outputs from another stack, but the DLQ is defined within the same stack, so cross-stack referencing is unnecessary and adds complexity.

64
MCQmedium

A developer runs the following AWS CLI query against a DynamoDB table named 'Orders' and receives a ValidationException: ``` aws dynamodb query \ --table-name Orders \ --key-condition-expression "OrderID = :orderID" \ --expression-attribute-values '{":orderID":{"S":"12345"}}' ``` What is the MOST likely cause?

A.The expression attribute values are incorrectly formatted
B.The table's partition key is not named 'OrderID'
C.The table does not exist
D.The query needs to use a sort key
AnswerB

A DynamoDB Query operation fundamentally requires that its KeyConditionExpression explicitly references the table's defined partition key attribute. If the table's actual partition key is named something other than 'OrderID' (e.g., 'CustomerID' or 'PK'), then attempting to use 'OrderID' in the KeyConditionExpression will result in a ValidationException. This error occurs because the query is trying to apply a key condition to an attribute that is not recognized as the table's primary partition key.

Why this answer

DynamoDB's Query operation requires that the KeyConditionExpression reference the table's actual partition key name exactly. If the Orders table's partition key is not named 'OrderID', the query fails with a ValidationException. The expression attribute values are formatted correctly, and a sort key is not required to query by partition key alone.

Exam trap

The trap here is that candidates often assume the error is due to missing a sort key or incorrect value formatting, but DynamoDB's strict schema validation means the partition key name must exactly match the table's definition, which is a common oversight.

How to eliminate wrong answers

Option A is wrong because expression attribute values (e.g., :v1) are syntactically correct in the query and DynamoDB would not throw an error for formatting unless they were missing or had invalid types. Option C is wrong because if the table did not exist, DynamoDB would return a 'ResourceNotFoundException', not a validation error related to key conditions. Option D is wrong because a query can be performed using only a partition key (with an equality condition) without a sort key; the error is not about missing a sort key but about an incorrect partition key name.

65
MCQhard

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application uses an Amazon RDS MySQL database. Recently, the application started experiencing frequent database connection timeouts. The development team discovered that the application is not closing database connections properly, leading to exhausted database connections. The team wants a solution that does not require code changes. Which option should they choose?

A.Configure Amazon RDS Proxy in front of the RDS instance and update the application to connect through the proxy.
B.Enable Multi-AZ on the RDS instance to handle failover and reduce connection timeouts.
C.Migrate the database to Amazon Aurora and enable Auto Scaling for read replicas.
D.Increase the max_connections parameter in the RDS parameter group to allow more concurrent connections.
AnswerA

Configuring Amazon RDS Proxy in front of the RDS instance is the most effective solution because it provides connection pooling and multiplexing. RDS Proxy maintains a pool of established database connections and reuses them for new application requests, significantly reducing the overhead on the database and making the application more resilient to transient connection issues or inefficient connection handling, such as connection leaks. This approach prevents connection exhaustion without requiring extensive application code changes to fix the underlying connection management issues.

Why this answer

Amazon RDS Proxy provides connection pooling, allowing the application to reuse database connections efficiently, reducing the number of open connections without code changes. Option B is incorrect: Multi-AZ provides high availability and failover but does not address connection leaks or exhaustion. Option C is incorrect: Migrating to Aurora with Auto Scaling for read replicas adds scalability for read traffic but does not fix connection leaks; it also requires migration effort.

Option D is incorrect: Increasing max_connections may temporarily alleviate the symptom but does not solve the underlying issue of connections not being closed, and it can lead to resource contention.

66
MCQmedium

A company is using Amazon API Gateway to expose a REST API. The API must authenticate requests using an external OAuth 2.0 provider. Which API Gateway feature should be used?

A.IAM authorization
B.Resource policy
C.Lambda authorizer
D.Amazon Cognito User Pools
AnswerC

A Lambda authorizer (formerly custom authorizer) is a powerful and flexible mechanism where API Gateway invokes a custom AWS Lambda function before forwarding the request to the backend. This Lambda function receives the incoming request's authorization header, allowing it to execute arbitrary custom logic to validate the external OAuth token. The function can perform tasks like calling an OAuth provider's introspection endpoint, verifying JWT signatures against public keys, or checking token claims, ultimately returning an IAM policy that grants or denies access to the API resources based on the token's validity.

Why this answer

A Lambda authorizer (formerly known as a custom authorizer) allows you to implement custom authentication logic using an external OAuth 2.0 provider. The Lambda function receives the OAuth 2.0 bearer token from the request, validates it against the external provider's token introspection endpoint or by verifying the JWT signature, and returns an IAM policy that grants or denies access to the API Gateway method.

Exam trap

The trap here is that candidates often confuse Amazon Cognito User Pools with a generic OAuth 2.0 integration, but Cognito is a specific AWS-managed IdP and cannot validate tokens issued by an external OAuth 2.0 provider like Auth0 or Okta.

How to eliminate wrong answers

Option A is wrong because IAM authorization uses AWS Signature Version 4 (SigV4) to sign requests with IAM credentials, which is designed for internal AWS authentication and cannot integrate with an external OAuth 2.0 provider. Option B is wrong because a resource policy controls access at the API level based on IP addresses, VPC endpoints, or AWS accounts, but it does not handle token validation or OAuth 2.0 flows. Option D is wrong because Amazon Cognito User Pools is a managed identity provider that issues its own JWTs, but the requirement explicitly states using an external OAuth 2.0 provider, and Cognito cannot delegate authentication to an arbitrary third-party OAuth 2.0 server.

67
MCQhard

A company has a microservices architecture running on Amazon ECS with Fargate. Each service exposes an API through an Application Load Balancer (ALB). The development team needs to implement canary deployments for one of the services. What is the MOST efficient way to achieve this?

A.Create two ECS services behind the same ALB, each with a different task definition, and use sticky sessions.
B.Use Amazon Route 53 weighted routing policies to distribute traffic between two ALBs.
C.Configure the ALB to use weighted target groups, each pointing to a different task set of the same ECS service.
D.Use AWS CodeDeploy with an ECS blue/green deployment configuration that supports canary traffic shifting.
AnswerD

AWS CodeDeploy does support blue/green deployments for ECS, including advanced traffic shifting strategies like canary. However, for a scenario focused purely on gradual traffic shifting between two versions of an application within the same ECS service, directly configuring weighted target groups on the ALB is a simpler and more native approach. CodeDeploy introduces an orchestration layer that, while powerful for complex deployment pipelines, might be overkill when the ALB's built-in capabilities can achieve the desired canary deployment with less overhead.

Why this answer

AWS CodeDeploy natively supports blue/green and canary deployments (e.g., ECSCanary10Percent5Minutes) for Amazon ECS. While ALB weighted target groups and ECS Task Sets are the underlying mechanisms used during these deployments, managing them manually (Option C) requires using the EXTERNAL deployment controller and writing custom orchestration code, which is highly inefficient. CodeDeploy automates this entire process seamlessly.

Exam trap

Candidates often think that because ALB supports weighted target groups, they should configure them manually for ECS canary deployments. However, for ECS, AWS CodeDeploy is the standard and most efficient tool to automate canary traffic shifting using those target groups.

How to eliminate wrong answers

Option A is wrong because creating two separate ECS services behind the same ALB with sticky sessions would route users to a fixed service based on session affinity, not allow gradual traffic shifting; it also adds operational overhead of managing multiple services. Option B is wrong because using Route 53 weighted routing between two ALBs introduces DNS-level latency and complexity, and does not support fine-grained traffic shifting at the application layer; it also requires managing two separate ALBs and DNS propagation delays. Option D is wrong because AWS CodeDeploy with blue/green deployment is designed for full traffic shifts (e.g., 10% then 100%) and requires additional setup and orchestration, making it less efficient than directly using ALB weighted target groups for canary deployments within a single ECS service.

68
MCQeasy

A developer needs to store a large number of binary files (e.g., images) that are accessed infrequently but must be retrievable within minutes. The storage solution should be cost-effective. Which Amazon S3 storage class is MOST suitable?

A.S3 Intelligent-Tiering
B.S3 One Zone-Infrequent Access
C.S3 Glacier Instant Retrieval
D.S3 Standard
AnswerC

S3 Glacier Instant Retrieval is specifically designed for long-lived, infrequently accessed data that requires millisecond retrieval, making it ideal for a "large number of binary files." It offers a significantly lower per-GB storage cost than S3 Standard or S3 Standard-IA, while still providing high durability across multiple Availability Zones. This class perfectly balances cost-efficiency for infrequent access with the necessity of immediate data availability when needed.

Why this answer

S3 Glacier Instant Retrieval is the most suitable because it is designed for long-lived, infrequently accessed data that requires retrieval in milliseconds (within minutes), offering a lower storage cost than S3 Standard while still providing rapid access. The question specifies 'retrievable within minutes' and 'cost-effective,' which aligns with Glacier Instant Retrieval's sub-second retrieval times and lower storage price point compared to S3 Standard or Intelligent-Tiering for data accessed rarely.

Exam trap

The trap here is that candidates confuse 'retrievable within minutes' with the longer retrieval times of S3 Glacier Flexible Retrieval (minutes to hours) or S3 Glacier Deep Archive (hours), and overlook that S3 Glacier Instant Retrieval provides millisecond retrieval while still being cost-effective for infrequently accessed data.

How to eliminate wrong answers

Option A is wrong because S3 Intelligent-Tiering automatically moves data between access tiers based on usage patterns, but it is not the most cost-effective for data that is accessed infrequently and predictably; it incurs a monitoring and automation fee that makes it more expensive than a direct infrequent-access class for this use case. Option B is wrong because S3 One Zone-Infrequent Access stores data in a single Availability Zone, which risks data loss if that AZ fails, and the question does not specify tolerance for such risk; it is also not optimized for retrieval within minutes as it is designed for infrequent access but with the same millisecond retrieval as Standard, making it less cost-effective than Glacier Instant Retrieval for this scenario. Option D is wrong because S3 Standard is designed for frequently accessed data with low latency and high throughput, but it is the most expensive storage class and not cost-effective for infrequently accessed data, violating the cost-effectiveness requirement.

69
MCQeasy

Refer to the exhibit. An IAM policy is attached to a user. What is the effect when the user tries to upload an object to s3://example-bucket/secret/file.txt?

A.The upload fails because the Deny statement explicitly denies access to the secret/ prefix.
B.The upload fails only if the user is not the bucket owner.
C.The upload succeeds because the Deny statement does not match the specific action.
D.The upload succeeds because the Allow statement grants s3:PutObject on the bucket.
AnswerA

The IAM policy evaluation logic dictates that an explicit Deny statement always takes precedence over any Allow statement. In this scenario, the Deny statement explicitly targets resources within the `secret/` prefix of `my-bucket` using `arn:aws:s3:::my-bucket/secret/*` and applies to all S3 actions (`s3:*`). Therefore, any attempt to upload an object to this specific prefix will be explicitly denied, regardless of other Allow permissions.

Why this answer

The Deny statement in the IAM policy explicitly denies the s3:PutObject action for any object with the prefix secret/ in the example-bucket. Since the user is trying to upload to s3://example-bucket/secret/file.txt, which matches the Deny condition, the request is denied regardless of any Allow statements. AWS IAM policy evaluation is explicit deny by default, meaning a Deny always overrides an Allow.

Exam trap

The trap here is that candidates often assume an Allow statement will always grant access, forgetting that an explicit Deny in IAM policies takes precedence over any Allow, even if the Deny is more specific.

How to eliminate wrong answers

Option B is wrong because the bucket owner status is irrelevant; IAM policies are evaluated based on the attached policy, not ownership, and the Deny statement applies to all users. Option C is wrong because the Deny statement explicitly matches the s3:PutObject action (implied by 'upload an object') and the secret/ prefix, so it does match the specific action. Option D is wrong because while the Allow statement grants s3:PutObject on the bucket, the explicit Deny for the secret/ prefix overrides it, causing the upload to fail.

70
MCQeasy

A developer needs to store application configuration data (key-value pairs) that can be accessed by multiple microservices running on EC2 instances. The configuration data changes infrequently but must be retrievable with low latency. Which AWS service should the developer use?

A.AWS Systems Manager Parameter Store
B.AWS AppConfig
C.Amazon S3
D.Amazon DynamoDB
AnswerA

AWS Systems Manager Parameter Store is a secure and scalable storage for configuration data and secrets. While it offers versioning and integration with other AWS services, it primarily functions as a parameter store. It lacks advanced features specifically designed for application configuration management, such as schema validation, phased deployments (e.g., canary or linear rollouts), or automatic rollback capabilities based on application health, which are crucial for safely deploying configuration changes at scale.

Why this answer

AWS Systems Manager Parameter Store is designed specifically to store configuration data (such as database strings, license codes, or general key-value pairs) and secrets. It provides a centralized, secure, and hierarchical store that can be easily accessed by EC2 instances and microservices with low latency. Standard parameters are free of charge, making it the ideal choice for infrequently changing configuration data.

Exam trap

Candidates often confuse AWS Systems Manager Parameter Store with AWS AppConfig or Secrets Manager. While AppConfig is used for dynamic configuration deployment (with features like gradual rollouts and validators), Parameter Store is the correct and standard service for simply storing and retrieving static or infrequently changing key-value configuration data.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Parameter Store is a parameter store for configuration data and secrets, but it lacks built-in features for controlled configuration deployments, validation, and local caching for low-latency retrieval; it is better suited for simple parameter storage without the deployment management capabilities of AppConfig. Option C is wrong because Amazon S3 is an object storage service that can store configuration files, but it does not provide low-latency retrieval for frequent access by microservices (due to HTTP-based access latency) and lacks native features for configuration validation, rollback, or managed deployments. Option D is wrong because Amazon DynamoDB is a NoSQL database designed for high-throughput, low-latency read/write operations on dynamic data, but it is overkill for infrequently changing configuration data and requires additional application logic for caching, validation, and deployment management, which AppConfig provides out of the box.

71
MCQhard

A company is using AWS CodeDeploy to deploy an application to an Auto Scaling group. The deployment fails with 'The overall deployment failed because too many individual instances failed deployment, too few healthy instances are available for deployment, or some instances in your deployment group are experiencing problems.' The developer wants to identify the specific error on a failed instance. Which AWS CLI command should the developer use?

A.aws deploy get-deployment
B.aws deploy get-deployment-instance
C.aws deploy list-deployments
D.aws deploy list-deployment-instances
AnswerB

This command is specifically designed to retrieve comprehensive details for a single target instance within a CodeDeploy deployment. It provides the instance's lifecycle event status (e.g., BeforeInstall, Install, ApplicationStop), any associated error messages, and the instance's overall status within that deployment. This granular information is crucial for diagnosing why a deployment failed on a particular instance, offering insights into specific script failures or configuration issues.

Why this answer

The `aws deploy get-deployment-instance` command retrieves detailed information about a single instance in a deployment group, including the specific error messages and lifecycle event logs that caused the instance to fail. This allows the developer to diagnose the root cause of the failure on a particular instance, which is exactly what is needed when the overall deployment fails with a generic error message.

Exam trap

The trap here is that candidates often confuse `list-deployment-instances` (which only returns instance IDs) with `get-deployment-instance` (which returns detailed error data), leading them to choose the list command when they actually need the detailed diagnostic output.

How to eliminate wrong answers

Option A is wrong because `aws deploy get-deployment` returns high-level deployment summary information (status, total instances, error count) but does not provide per-instance error details or lifecycle event logs. Option C is wrong because `aws deploy list-deployments` only lists deployment IDs and basic metadata (e.g., application name, creation time) for a given application or deployment group, not instance-level failure information. Option D is wrong because `aws deploy list-deployment-instances` returns a list of instance IDs associated with a deployment, but does not include the detailed error messages or lifecycle event logs needed to identify the specific error on a failed instance.

72
MCQeasy

A developer is writing an AWS Lambda function in Python that needs to download a file from Amazon S3, process it, and upload the result to a different S3 bucket. The function currently runs within the default 3-second timeout, but the developer expects the file size to increase. What is the MOST cost-effective way to handle the increase in processing time?

A.Increase the Lambda function's timeout to a value higher than the expected processing time.
B.Increase the Lambda function's timeout to 15 minutes.
C.Use Lambda provisioned concurrency to keep the function warm.
D.Refactor the code to use AWS Step Functions to orchestrate the processing.
AnswerA

AWS Lambda functions have a configurable timeout setting, which defines the maximum duration a function can execute before being terminated. By increasing this timeout to a value exceeding the anticipated processing time, the developer directly resolves the issue of the function being prematurely terminated. This is the most straightforward and cost-effective approach for a single Lambda function needing more execution time, without introducing additional architectural complexity.

Why this answer

Increasing the Lambda function's timeout is the most cost-effective solution because it directly addresses the expected increase in processing time without incurring additional costs. Lambda pricing is based on the number of invocations and duration (in GB-seconds), so extending the timeout only charges for the actual time the function runs, not for idle time or additional services. This approach avoids the complexity and cost of Step Functions or provisioned concurrency, which would add unnecessary overhead for a simple sequential task.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing Step Functions or provisioned concurrency, thinking they are needed for long-running tasks, when the simplest and most cost-effective fix is merely adjusting the Lambda timeout.

How to eliminate wrong answers

Option B is wrong because increasing the timeout to 15 minutes is excessive and may exceed the Lambda maximum execution timeout of 15 minutes, but more importantly, it does not address cost-effectiveness—it simply sets a maximum limit without considering the actual processing time. Option C is wrong because provisioned concurrency is designed to reduce cold start latency for latency-sensitive applications, not to handle longer processing times, and it incurs additional costs for keeping functions initialized. Option D is wrong because refactoring to use AWS Step Functions introduces unnecessary complexity and cost for a simple download-process-upload workflow; Step Functions are better suited for orchestrating multiple independent tasks or handling retries and error handling across services, not for extending a single function's execution time.

73
MCQhard

A company uses Amazon API Gateway with a Lambda authorizer to control access to its APIs. The Lambda authorizer returns an IAM policy that grants access to the API. Recently, the company noticed that some API calls are being throttled due to high latency from the authorizer. What is the MOST effective way to reduce latency?

A.Enable caching for the Lambda authorizer responses.
B.Use a custom authorizer instead of a Lambda authorizer.
C.Reduce the TTL of the authorizer cache.
D.Increase the memory allocated to the Lambda authorizer function.
AnswerA

Enabling caching for Lambda authorizer responses significantly optimizes API Gateway performance and cost. Once an authorizer successfully authenticates a request and returns a policy, API Gateway stores this decision for a configurable duration. Subsequent requests with the same identity source within the cache's Time-To-Live (TTL) period will bypass the Lambda authorizer invocation entirely, drastically reducing latency and Lambda execution costs.

Why this answer

Enabling caching for the Lambda authorizer responses allows API Gateway to reuse the IAM policy returned by the authorizer for subsequent requests that match the same cache key, without invoking the Lambda function again. This eliminates the latency of the authorizer invocation on cache hits, directly addressing the throttling caused by high authorizer latency.

Exam trap

The trap here is that candidates may assume increasing Lambda memory (Option D) is the universal fix for Lambda performance issues, but in this context the latency stems from the invocation overhead and network round-trip, not from CPU-bound processing, making caching the more effective solution.

How to eliminate wrong answers

Option B is wrong because 'custom authorizer' is an ambiguous term; in API Gateway, a Lambda authorizer is already a type of custom authorizer, and switching to a different implementation (e.g., a Cognito user pool authorizer) would not necessarily reduce latency and may not support the required IAM policy-based access control. Option C is wrong because reducing the TTL of the authorizer cache would cause the cache to expire more frequently, increasing the number of Lambda invocations and potentially worsening latency and throttling. Option D is wrong because while increasing Lambda memory can reduce execution time for compute-intensive tasks, the primary bottleneck here is the invocation overhead and network round-trip, not CPU-bound processing; caching addresses the root cause more effectively.

74
MCQeasy

A company uses AWS CodeCommit and wants to automatically trigger a build in AWS CodePipeline when code is pushed to the master branch. Which action should be taken?

A.Configure a CloudWatch Events rule to start the pipeline on repository changes
B.Add a webhook in CodeCommit to directly invoke CodePipeline
C.Set up a scheduled pipeline that polls CodeCommit every minute
D.Use an S3 trigger to start the pipeline when code is uploaded
AnswerA

CloudWatch Events (now Amazon EventBridge) is the standard and most efficient mechanism for integrating AWS CodeCommit with AWS CodePipeline. CodeCommit automatically publishes events, such as ReferenceUpdated for code pushes, to CloudWatch Events. A rule can then be configured to filter these specific events from the CodeCommit repository and branch, triggering a CodePipeline execution as its target. This creates a real-time, event-driven CI/CD workflow.

Why this answer

AWS CodePipeline can be configured to automatically start when changes are pushed to a CodeCommit repository by using an Amazon CloudWatch Events rule. The rule listens for CodeCommit repository state changes (e.g., 'ReferenceCreated' or 'ReferenceUpdated' events on the master branch) and targets the pipeline as a CloudWatch Events target, triggering the pipeline execution without polling or manual intervention.

Exam trap

The trap here is that candidates often confuse CodeCommit's integration with webhooks (which work with external Git providers) and assume CodeCommit supports them natively, or they overcomplicate the solution by suggesting polling or S3 triggers instead of using the native CloudWatch Events integration.

How to eliminate wrong answers

Option B is wrong because CodeCommit does not support webhooks to directly invoke CodePipeline; webhooks are used with third-party Git providers like GitHub or Bitbucket, not with CodeCommit. Option C is wrong because scheduling a pipeline to poll every minute is inefficient and not a native integration; CodePipeline does not natively poll CodeCommit at a fixed interval, and CloudWatch Events provides a real-time, event-driven approach. Option D is wrong because an S3 trigger is used for S3 bucket events, not for CodeCommit repository changes; CodeCommit events are not published to S3, and this approach would require unnecessary intermediate steps.

75
MCQmedium

A developer is building a serverless application using AWS SAM that includes an API Gateway REST API and a Lambda function. The developer wants to pass environment variables to the Lambda function based on the deployment stage (dev/prod). The stage name is provided as a SAM parameter. How should the developer define this in the SAM template?

A.Define a SAM Parameter for the stage name, and reference it in the Lambda function's Environment property
B.Use the Globals section of the SAM template to set environment variables
C.Hard-code the environment variables with different values in the template
D.Use an AWS Systems Manager Parameter Store parameter and reference it in the function
AnswerA

Defining a SAM Parameter for the stage name is the correct and recommended approach. This allows the stage name to be passed as an input during the `sam deploy` command, which then populates a CloudFormation parameter. The Lambda function's `Environment.Variables` property can then reference this parameter using `!Ref` or `Fn::Sub`, dynamically injecting the correct stage name into the function's runtime environment based on the deployment target.

Why this answer

AWS SAM allows you to define parameters (e.g., StageName) and reference them directly in the Lambda function's Environment property using CloudFormation intrinsic functions like !Ref. This enables dynamic injection of environment variables based on the deployment stage without modifying the template structure, aligning with Infrastructure as Code best practices for multi-environment deployments.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing Parameter Store (Option D) for dynamic values, missing that SAM parameters are the simplest native mechanism for stage-specific environment variables without external service dependencies.

How to eliminate wrong answers

Option B is wrong because the Globals section sets default values for all functions in the template, but it cannot dynamically vary environment variables per deployment stage without additional logic like conditions or parameters, making it unsuitable for stage-specific values. Option C is wrong because hard-coding environment variables for each stage would require maintaining separate templates or manual edits, violating the principle of reusable, parameterized templates and increasing error risk. Option D is wrong because while AWS Systems Manager Parameter Store can store values, referencing it directly in the function does not inherently tie the value to the SAM deployment stage; you would still need a parameter or mapping to select the correct Parameter Store path per stage, making Option A more straightforward.

Page 1 of 6 · 388 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Dev AWS Services questions.