Courseiva

CCNA Dev AWS Services Questions

75 of 388 questions · Page 5/6 · Dev AWS Services topic · Answers revealed

301
MCQeasy

A developer is creating a new DynamoDB table to store order data. The orders have a unique order ID and are retrieved by order ID. Occasionally, the developer needs to query orders by customer ID. Which design approach would minimize costs and provide the fastest queries?

A.Use the order ID as the partition key and create a global secondary index on customer ID
B.Use the customer ID as the partition key and order ID as the sort key
C.Use the order ID as the partition key and scan the table for customer ID queries
D.Use the customer ID as the partition key and create a local secondary index on order ID
AnswerA

This design effectively supports two distinct access patterns: retrieving a specific order by its unique order ID using a highly efficient GetItem operation, and querying all orders associated with a particular customer ID. By establishing a Global Secondary Index (GSI) with customer ID as its partition key, DynamoDB can efficiently retrieve all items matching that customer, optimizing performance and minimizing read capacity unit consumption for both primary and secondary query types.

Why this answer

Using the order ID as the partition key ensures the most efficient primary key access for the primary query pattern (retrieving by order ID). Creating a Global Secondary Index (GSI) on customer ID allows efficient querying by customer ID without scanning the base table, and GSIs have separate read/write capacity from the base table, so you only pay for the index when it is used. This design minimizes costs by avoiding unnecessary scans and provides the fastest queries for both access patterns.

Exam trap

The trap here is that candidates often choose Option B (customer ID as partition key) thinking it naturally supports both access patterns, but they overlook the hot partition problem and the fact that retrieving a single order by order ID would require a scan or a query with a known customer ID, which is not always available.

How to eliminate wrong answers

Option B is wrong because using customer ID as the partition key would cause all orders for the same customer to be stored in the same partition, leading to hot partitions and potential throttling, and it does not provide efficient retrieval by order ID (which would require a scan or a query with a known customer ID). Option C is wrong because scanning the entire table to find orders by customer ID is extremely inefficient and costly, as it reads every item in the table and incurs read capacity for all items, even those not matching the query. Option D is wrong because a Local Secondary Index (LSI) requires the same partition key as the base table (customer ID), which would still cause hot partitions for high-volume customers, and LSIs share the base table's read/write capacity, so they do not provide the same cost flexibility as a GSI.

302
MCQhard

A developer is migrating a monolithic application to a microservices architecture on AWS. The application uses a relational database. The developer wants to use Amazon RDS for the database and needs to ensure that each microservice can only access its own set of tables. Which approach should the developer take?

A.Create a single RDS instance with a separate database per microservice.
B.Use RDS with IAM database authentication and create database users with limited privileges for each microservice.
C.Use RDS in a VPC and restrict network access per microservice using security groups.
D.Use Amazon RDS Proxy to control access.
AnswerB

AWS IAM database authentication integrates directly with IAM, allowing microservices to authenticate using IAM roles or users, eliminating the need for hardcoded database credentials. This method enables the creation of highly granular database users with specific permissions (e.g., SELECT on tableA, INSERT on tableB), ensuring each microservice can only access the precise tables and operations it requires. This robust, fine-grained access control is essential for securing a microservices architecture.

Why this answer

IAM database authentication allows the developer to create database users with granular, table-level privileges using standard SQL GRANT statements, ensuring each microservice can only access its own set of tables. By combining IAM roles with database user credentials, the developer can enforce least-privilege access without sharing a single database user across services. This approach directly addresses the requirement for per-microservice table isolation while leveraging RDS's native authentication and authorization capabilities.

Exam trap

The trap here is that candidates often confuse network-level isolation (security groups) with database-level authorization, assuming that restricting network access per microservice is sufficient to enforce table-level separation, when in fact security groups cannot differentiate between tables within the same database instance.

How to eliminate wrong answers

Option A is wrong because creating a separate database per microservice on a single RDS instance does not prevent a microservice from connecting to another microservice's database if it has the same database user credentials or network access; it only provides logical separation, not access control. Option C is wrong because security groups control network-layer access to the RDS instance as a whole, not to individual tables or databases within it; once a microservice can connect to the RDS endpoint, it can access any table unless further database-level permissions are enforced. Option D is wrong because Amazon RDS Proxy manages connection pooling and provides some IAM authentication support, but it does not enforce table-level access control; it still relies on the underlying database user permissions for authorization.

303
Multi-Selectmedium

A developer is designing a microservices architecture using Amazon ECS with Fargate. The application needs to store and retrieve user session data. Which TWO AWS services can be used to store session state?

Select 2 answers
A.Amazon DynamoDB
B.Amazon ElastiCache for Redis
C.Amazon S3
D.Amazon EFS
E.Amazon RDS for MySQL
AnswersA, B

Amazon DynamoDB is a fully managed, serverless NoSQL database service offering single-digit millisecond performance at any scale. Its key-value data model is exceptionally well-suited for storing session state, where a session ID serves as the primary key for rapid retrieval and updates of associated user data. This low-latency, highly available, and scalable nature ensures a consistent and responsive user experience across distributed microservices without operational overhead.

Why this answer

Amazon DynamoDB (A) is correct because it is a fully managed, low-latency key-value NoSQL database that is commonly used to store session state for microservices, allowing fast reads/writes keyed by session ID with automatic scaling and TTL-based expiration. Amazon ElastiCache for Redis (B) is also correct because Redis is an in-memory data store with sub-millisecond latency and native support for data structures and key expiration, making it a standard choice for session caching and storage in containerized ECS/Fargate architectures. Amazon S3 (C) is not suitable because it is object storage with higher latency and eventual consistency characteristics, not designed for frequent small session reads/writes.

Amazon EFS (D) is a shared file system for POSIX workloads and is not intended as a low-latency session state store. Amazon RDS for MySQL (E) is a relational database that can technically store sessions, but it is not the typical high-throughput, low-latency session store for microservices and is not marked correct here.

Exam trap

The exam frequently tests your ability to choose the most performant and scalable options for session state. While you *can* technically store session data in RDS or S3, they are not optimized for the high-frequency, low-latency read/write patterns of session state. DynamoDB and ElastiCache are the standard AWS best-practice recommendations for this use case.

304
MCQhard

A developer wants a Lambda function to process SQS messages in batches but avoid losing the whole batch when only one record fails. Which feature should be enabled?

A.Partial batch response for SQS event source mapping
B.Reserved concurrency of one
C.Maximum message size increase
D.SQS short polling
AnswerA

Partial batch response for SQS event source mapping directly addresses the challenge of handling failures within a batch of messages processed by a Lambda function. When enabled, the Lambda function can return a list of message IDs that failed processing, allowing SQS to only return those specific messages to the queue for retry. This prevents successful messages within the same batch from being reprocessed, significantly improving efficiency, reducing costs, and simplifying error handling logic.

Why this answer

Partial batch response for SQS event source mapping allows the Lambda function to report which messages in a batch failed processing. When enabled, Lambda retries only the failed messages instead of the entire batch, preventing successful messages from being reprocessed or lost. This is achieved by returning a `batchItemFailures` array in the function's response, which tells Lambda which message IDs to retry.

Exam trap

The trap here is that candidates may confuse partial batch response with SQS dead-letter queues or retry policies, but the key differentiator is that partial batch response is a Lambda event source mapping feature that specifically allows per-message failure handling within a batch.

How to eliminate wrong answers

Option B is wrong because reserved concurrency of one limits the Lambda function to a single concurrent execution, which does not affect how individual messages within a batch are handled; it only throttles overall throughput. Option C is wrong because maximum message size increase is a queue-level setting in SQS that controls the maximum payload size (up to 256 KB for standard queues), not a mechanism for handling partial batch failures. Option D is wrong because SQS short polling returns immediately with available messages but does not provide any per-message failure handling within a batch; it only affects message retrieval latency.

305
MCQeasy

A developer is creating an AWS Lambda function that processes files uploaded to an S3 bucket. The developer wants to invoke the Lambda function automatically when a new file is uploaded. Which approach should the developer use?

A.Use Amazon API Gateway to expose an endpoint and have S3 call it.
B.Configure S3 to send events to an SQS queue, and configure Lambda to poll the queue.
C.Configure S3 event notifications to invoke the Lambda function directly.
D.Use Amazon CloudWatch Events to trigger Lambda on S3 PUT events.
AnswerC

Configuring S3 event notifications to invoke the Lambda function directly is the most straightforward and recommended approach for processing S3 object events. S3's native event notification feature allows a bucket to publish events, such as `s3:ObjectCreated:Put`, directly to an AWS Lambda function. This establishes a direct, asynchronous invocation model where S3 acts as the event source, pushing events to Lambda without requiring any intermediary services.

Why this answer

S3 can directly invoke a Lambda function via S3 event notifications. When a new object is created in the bucket, S3 publishes a notification with the event type `s3:ObjectCreated:*` and the Lambda function is triggered asynchronously. This is the simplest and most direct integration for this use case, requiring no intermediate services.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing an indirect pattern like SQS or CloudWatch Events, not realizing that S3 has a built-in, direct integration with Lambda for event notifications.

How to eliminate wrong answers

Option A is wrong because API Gateway is an unnecessary intermediary; S3 can invoke Lambda directly without needing an HTTP endpoint. Option B is wrong because while S3 can send events to SQS and Lambda can poll the queue, this adds complexity and latency for a simple file-processing scenario where direct invocation is supported. Option D is wrong because CloudWatch Events (now Amazon EventBridge) can trigger Lambda on S3 events, but this requires setting up a rule and is an indirect pattern; S3 event notifications are the native, simpler approach.

306
MCQhard

A company runs a containerized application on Amazon ECS with Fargate launch type. The application needs to access an Amazon RDS MySQL database using credentials stored in AWS Secrets Manager. The ECS task role has the following IAM policy: {"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":["secretsmanager:GetSecretValue"],"Resource":"arn:aws:secretsmanager:us-east-1:123456789012:secret:prod-db-*"}]}. The application fails to retrieve the secret with an AccessDeniedException. What is the most likely cause?

A.The task execution role does not have permission to retrieve the secret.
B.The secret's resource-based policy denies access to the task role.
C.The task is in a private subnet without a VPC endpoint to Secrets Manager.
D.The secret name does not match the pattern in the policy.
AnswerB

AWS Secrets Manager supports resource-based policies, which are attached directly to the secret itself and specify which principals (like an ECS Task Role) are allowed or denied access. Even if the ECS Task Role has an identity-based policy that explicitly grants permission to retrieve secrets, an explicit Deny statement in the secret's resource-based policy will always override any Allow statements, effectively blocking access for the task role. This provides a powerful mechanism for fine-grained access control at the resource level.

Why this answer

The IAM policy on the ECS task role allows access to secrets matching the pattern `prod-db-*`. However, if the secret has a resource-based policy that explicitly denies access to the task role, that denial overrides the IAM allow, causing an AccessDeniedException. AWS Secrets Manager evaluates both identity-based policies (task role) and resource-based policies, and an explicit deny in either results in denial.

Exam trap

The trap here is that candidates confuse the task execution role with the task role, or assume network connectivity issues (VPC endpoints) are the cause when the error is clearly an IAM permissions denial.

How to eliminate wrong answers

Option A is wrong because the task execution role is used to pull container images and write logs, not to retrieve secrets; the task role (which has the policy shown) is used for application-level API calls like GetSecretValue. Option C is wrong because while a VPC endpoint can improve network connectivity, it is not required for Fargate tasks to reach Secrets Manager over the public internet or via NAT gateway; the error is an AccessDeniedException, not a network timeout. Option D is wrong because the secret name matches the pattern `prod-db-*` in the policy; the error is an access denial, not a resource mismatch.

307
MCQhard

A developer is investigating why an AWS Lambda function is not writing logs to CloudWatch Logs. The function has been invoked multiple times, but the log group shows 0 stored bytes. What is the most likely cause?

A.The CloudWatch Logs log group does not exist.
B.The Lambda execution role lacks permissions to write to CloudWatch Logs.
C.The Lambda function is failing before any logging code is executed.
D.The Lambda function is configured to use a different log group name.
AnswerB

For an AWS Lambda function to successfully send its runtime logs and any application-specific output (e.g., from `console.log`) to CloudWatch Logs, its associated IAM execution role must possess specific permissions. Crucially, these include `logs:CreateLogStream` to create a new log stream within the log group and `logs:PutLogEvents` to send log data to that stream. Without these explicit permissions, the function will execute, but its logging attempts will silently fail, resulting in no log entries appearing in CloudWatch.

Why this answer

The most likely cause is that the Lambda execution role lacks the necessary IAM permissions to write logs to CloudWatch Logs. Without permissions such as `logs:CreateLogGroup`, `logs:CreateLogStream`, and `logs:PutLogEvents`, the Lambda function cannot create the log group or stream, nor can it write log events, resulting in 0 stored bytes despite successful invocations.

Exam trap

The trap here is that candidates assume a missing log group (Option A) is the root cause, when in fact the log group is automatically created if the IAM permissions are correct, making the permission issue the more fundamental problem.

How to eliminate wrong answers

Option A is wrong because the log group is automatically created by the Lambda service on the first invocation if the execution role has the required permissions; its absence is a symptom, not the root cause. Option C is wrong because if the function were failing before any logging code, the Lambda runtime itself would still attempt to write execution logs (e.g., START, END, REPORT messages) to CloudWatch, which would produce stored bytes. Option D is wrong because the log group name is predetermined by the Lambda service (e.g., /aws/lambda/<function-name>) and cannot be changed by the developer; a different log group name would not prevent logs from being written to the default group.

308
MCQeasy

A developer is using AWS Lambda to process messages from an Amazon SQS queue. The function needs to access an Amazon DynamoDB table. What is the MOST secure way to grant the Lambda function access to DynamoDB?

A.Use the Lambda function's execution role to grant full administrative access to DynamoDB.
B.Store the AWS access key and secret access key as environment variables in the Lambda function.
C.Assign an IAM role to the Lambda function with a policy that grants the required DynamoDB permissions.
D.Create an IAM user with DynamoDB access and use its credentials in the Lambda function.
AnswerC

Assigning an IAM role to the Lambda function with a precisely scoped policy is the secure and recommended method for granting AWS service permissions. This approach leverages temporary credentials automatically managed by AWS, eliminating the need to store static access keys. The IAM policy can be crafted to adhere strictly to the principle of least privilege, allowing the function only the specific DynamoDB actions (e.g., dynamodb:PutItem, dynamodb:GetItem) on designated resources it requires to perform its task.

Why this answer

AWS Lambda uses an IAM execution role to securely obtain temporary credentials via the AWS Security Token Service (STS). By attaching a policy that grants only the required DynamoDB actions (e.g., GetItem, PutItem) on specific tables, you follow the principle of least privilege. This avoids hardcoding long-term credentials and eliminates the risk of credential exposure.

Exam trap

The trap here is that candidates may think storing credentials as environment variables is acceptable for simplicity, but the exam emphasizes that IAM roles with least-privilege policies are the most secure and AWS-recommended approach for granting permissions to AWS services like Lambda.

How to eliminate wrong answers

Option A is wrong because granting full administrative access (e.g., dynamodb:* on all resources) violates least privilege and could allow unintended actions like deleting tables. Option B is wrong because storing AWS access keys and secret access keys as environment variables exposes long-term credentials in plaintext, increasing the risk of leakage through logs or function output. Option D is wrong because creating an IAM user and embedding its credentials in the function requires managing long-term keys, which is less secure than using an execution role that automatically rotates temporary credentials.

309
MCQmedium

A company is building a serverless application using AWS Lambda and Amazon API Gateway. The application needs to process user uploads to an S3 bucket. The Lambda function should be invoked only when new objects are created in the bucket. Which service should be used to trigger the Lambda function?

A.Amazon Kinesis Data Streams
B.Amazon S3 event notifications
C.Amazon CloudWatch Events
D.Amazon Simple Queue Service (SQS)
AnswerB

Amazon S3 event notifications provide a direct, highly efficient, and serverless mechanism to trigger AWS Lambda functions in response to various object lifecycle events, such as object creation (e.g., `s3:ObjectCreated:*`). By configuring an event notification on an S3 bucket, S3 directly invokes the specified Lambda function with a detailed event payload. This eliminates the need for polling, custom code, or intermediary services, making it the most straightforward and cost-effective solution for reacting to S3 object uploads.

Why this answer

Amazon S3 event notifications can be configured to trigger AWS Lambda functions when specific events occur in an S3 bucket, such as when a new object is created (e.g., s3:ObjectCreated:*). This is the native and most direct way to invoke a Lambda function in response to S3 object uploads. It requires no additional polling or infrastructure and is highly scalable.

Exam trap

DVA-C02 often tests the confusion between S3 event notifications and other services like SQS or CloudWatch Events; candidates may overcomplicate by choosing SQS when S3 event notifications directly trigger Lambda.

How to eliminate wrong answers

Option A is wrong because Amazon Kinesis Data Streams is used for real-time streaming data, not for triggering Lambda on S3 object creation; it would require custom integration. Option C is wrong because Amazon CloudWatch Events (now Amazon EventBridge) can trigger Lambda on a schedule or in response to AWS API calls, but it does not natively capture S3 object creation events without additional configuration and is not the primary service for this use case. Option D is wrong because Amazon SQS is a message queue that decouples components; it does not directly trigger Lambda on S3 events unless you configure S3 to send notifications to SQS and then have Lambda poll the queue, which adds unnecessary complexity.

310
MCQmedium

A developer is using Amazon SQS to decouple microservices. The consumer service processes messages from the queue. To reduce processing time, the developer wants to receive multiple messages in a single API call. What is the maximum number of messages that can be received at once?

A.5
B.100
C.20
D.10
AnswerD

This is the correct maximum value for the `MaxNumberOfMessages` parameter when calling the SQS `ReceiveMessage` API. Amazon SQS allows consumers to retrieve up to 10 messages in a single batch, which helps reduce the number of API calls, minimize network overhead, and improve overall processing efficiency for microservices. Requesting 10 messages optimizes throughput while adhering to the service's defined limits.

Why this answer

Amazon SQS allows a consumer to retrieve up to 10 messages in a single ReceiveMessage API call. This is the hard limit enforced by the SQS service, regardless of the queue type (standard or FIFO). Using this maximum batch size can reduce the number of API calls and improve throughput, but each message must still be processed individually and deleted after processing.

Exam trap

The trap here is confusing the SQS ReceiveMessage batch limit (10) with the SQS SendMessageBatch limit (10) or the Lambda event source mapping batch size (up to 10,000), leading candidates to pick 5, 20, or 100.

How to eliminate wrong answers

Option A is wrong because 5 is the maximum number of messages that can be sent in a single SendMessageBatch API call, not received. Option B is wrong because 100 is the maximum number of messages that can be sent or received in a single batch for Amazon SNS or Kinesis, but SQS limits ReceiveMessage to 10. Option C is wrong because 20 is the maximum batch size for AWS Lambda event source mappings when polling an SQS queue, not the limit for a single ReceiveMessage API call.

311
MCQhard

A developer is writing a Lambda function that processes messages from an Amazon SQS queue. The function must ensure that if a message fails to process, it is retried later without blocking other messages. The queue is a standard queue. Which configuration should the developer use?

A.Use a Lambda event source mapping with a batch size greater than 1 and enable partial batch responses by returning batchItemFailures.
B.Configure a dead-letter queue on the SQS queue and set maxReceiveCount to 1.
C.Set the SQS queue's visibility timeout to 0 seconds so failed messages become immediately visible again.
D.Configure the Lambda event source mapping with a batch size of 1 and set the maximumBatchingWindowInSeconds to 0.
AnswerA

For standard queues, enabling partial batch responses lets the function return a list of failed message IDs. Lambda deletes only the successfully processed messages and returns the failed ones to the queue for retry, so one bad message does not force the entire batch to be reprocessed.

Why this answer

For standard queues, Lambda event source mappings support partial batch responses. When the function returns a batchItemFailures list, Lambda marks only those messages as failed, deletes the rest, and allows the failed messages to be retried according to the queue's visibility timeout and redrive policy.

Exam trap

The trap here is believing that any batch failure automatically retries only the failed message, when without partial batch responses the entire batch is retried and duplicates can occur.

312
MCQmedium

A company has a Lambda function that processes records from an SQS queue. The function is failing intermittently with timeout errors. The processing time per record varies, but the SQS queue has a visibility timeout of 30 seconds. The Lambda function has a timeout of 1 minute. What is the MOST likely cause of the timeout errors?

A.The Lambda function's reserved concurrency is set too low.
B.The SQS queue has too many messages causing Lambda to throttle.
C.The SQS visibility timeout is shorter than the Lambda function timeout.
D.The SQS queue's default visibility timeout of 30 seconds is too long.
AnswerC

If the SQS visibility timeout is configured to be shorter than the Lambda function's execution timeout, a message being processed by Lambda can become visible again in the queue before the function successfully completes its work. This scenario can lead to other Lambda instances, or even the same one, picking up and attempting to process the identical message again. Such duplicate processing can cause resource contention, unexpected behavior, and ultimately result in the original or subsequent Lambda invocations timing out as they struggle to complete the task or handle redundant operations.

Why this answer

When the SQS visibility timeout (30 seconds) is shorter than the Lambda function timeout (1 minute), the message becomes visible again in the queue before the function finishes processing it. This causes the same message to be picked up by another consumer (or the same Lambda invocation) while the original invocation is still running, leading to duplicate processing and eventual timeout errors as the function repeatedly attempts to process the same record.

Exam trap

The trap here is that candidates often confuse timeout errors with throttling or concurrency issues, but the specific interplay between SQS visibility timeout and Lambda function timeout is a classic DVA-C02 pitfall that tests understanding of asynchronous message processing lifecycle.

How to eliminate wrong answers

Option A is wrong because reserved concurrency limits the maximum number of concurrent Lambda executions, but timeout errors are not caused by concurrency limits—they occur when the function execution exceeds its configured timeout. Option B is wrong because Lambda throttling occurs when the number of concurrent invocations exceeds the account or function concurrency limit, not from too many messages in the queue; throttling results in invocation failures (e.g., 429 errors), not timeout errors within the function. Option D is wrong because a 30-second visibility timeout is not too long; in fact, it is too short relative to the Lambda timeout, causing premature message reappearance—a longer visibility timeout would help prevent the issue.

313
MCQhard

A company uses AWS Lambda functions behind an API Gateway REST API. The Lambda functions are written in Python and use the boto3 SDK to interact with DynamoDB. After a recent deployment, some users report sporadic 502 Bad Gateway errors when calling the API. The Lambda function logs show occasional 'AccessDeniedException' errors. What is the most likely cause and solution?

A.The Lambda function is timing out. Increase the timeout value in the Lambda configuration.
B.The DynamoDB table is throttling requests. Enable auto-scaling for the table.
C.The Lambda execution role lacks permissions to access DynamoDB. Update the role to include the necessary DynamoDB actions.
D.The API Gateway request is too large. Set the payload size limit higher in API Gateway settings.
AnswerC

An "AccessDeniedException" from DynamoDB, when invoked by a Lambda function, unequivocally indicates that the Lambda function's IAM execution role does not possess the required permissions to perform the requested DynamoDB actions. Granting specific DynamoDB permissions, such as "dynamodb:GetItem" or "dynamodb:PutItem", to the Lambda's execution role will resolve this authorization error, allowing the function to interact with the table successfully.

Why this answer

The 'AccessDeniedException' error in the Lambda logs indicates that the Lambda function's execution role does not have the necessary IAM permissions to perform the requested DynamoDB operation. This is a common misconfiguration after deployments where the role or its attached policies are not updated to include the required DynamoDB actions (e.g., dynamodb:GetItem, dynamodb:PutItem). The 502 Bad Gateway from API Gateway is a direct consequence of the Lambda function failing internally due to this permission error.

Exam trap

The trap here is that candidates often confuse 'AccessDeniedException' with throttling or timeout errors, but the specific error message in the logs directly points to an IAM permissions issue, not a capacity or performance problem.

How to eliminate wrong answers

Option A is wrong because a timeout would produce a 'Task timed out' error in the logs, not an 'AccessDeniedException'. Option B is wrong because throttling from DynamoDB would result in 'ProvisionedThroughputExceededException' errors, not 'AccessDeniedException'. Option D is wrong because a request payload size issue would cause a '413 Request Entity Too Large' error from API Gateway, not a 502 Bad Gateway, and the Lambda logs would not show an 'AccessDeniedException'.

314
MCQmedium

A developer is deploying a new version of an AWS Lambda function. The function uses an environment variable for a database password. The developer wants to securely store the password and automatically rotate it. Which combination of AWS services should the developer use?

A.Use AWS KMS to generate a data key and store it in the Lambda environment variable.
B.Store the password in AWS Secrets Manager and retrieve it in the Lambda function using the AWS SDK.
C.Store the password in AWS Systems Manager Parameter Store and reference it in the Lambda function.
D.Encrypt the password using AWS KMS and store it in Amazon DynamoDB.
AnswerB

AWS Secrets Manager is the most appropriate and secure solution for storing and retrieving sensitive credentials like passwords in Lambda functions. It is purpose-built for secret management, offering features such as automatic rotation of secrets, fine-grained access control, and comprehensive auditing. Lambda functions can securely retrieve these secrets at runtime using the AWS SDK, ensuring credentials are never hardcoded or exposed in environment variables.

Why this answer

AWS Secrets Manager is specifically designed to securely store secrets like database passwords, supports automatic rotation of secrets, and integrates with Lambda via the AWS SDK to retrieve the secret at runtime. This ensures the password is never hardcoded or exposed in environment variables, and rotation can be scheduled without code changes.

Exam trap

The trap here is that candidates may confuse Parameter Store (Option C) with Secrets Manager, but Parameter Store lacks built-in automatic rotation, which is explicitly required in the question, making Secrets Manager the only correct choice.

How to eliminate wrong answers

Option A is wrong because AWS KMS generates data keys for encryption, not for storing secrets, and storing a data key in an environment variable does not provide automatic rotation or secure secret management. Option C is wrong because AWS Systems Manager Parameter Store can store passwords but does not natively support automatic rotation of secrets; it requires custom solutions or integration with Secrets Manager for rotation. Option D is wrong because storing an encrypted password in DynamoDB adds unnecessary complexity, does not provide automatic rotation, and requires custom encryption/decryption logic, whereas Secrets Manager handles both securely.

315
Multi-Selecteasy

Which TWO of the following are benefits of using Amazon API Gateway to manage APIs? (Choose two.)

Select 2 answers
A.Built-in caching of database queries to Amazon RDS
B.Direct integration with Amazon S3 for file storage
C.Throttling and rate limiting of API requests
D.Generation of client SDKs for multiple programming languages
E.Automatic connection pooling for backend databases
AnswersC, D

Amazon API Gateway provides robust capabilities for throttling and rate limiting API requests, which is crucial for protecting backend services from being overwhelmed and ensuring fair usage among consumers. You can configure global request limits, burst limits, and even define usage plans with specific quotas and throttles per API key. This prevents denial-of-service attacks and maintains API stability under high load.

Why this answer

Option C is correct because API Gateway provides built-in throttling and rate limiting through usage plans and API keys, allowing you to control request rates per client and protect backend services from being overwhelmed. Option D is correct because API Gateway can automatically generate client SDKs for multiple programming languages (such as Java, JavaScript, Python, and iOS/Android) from an API's definition, simplifying client integration. Option A is not a feature of API Gateway, which does not cache database queries to Amazon RDS; it can cache API responses at the stage level, but not RDS queries.

Option B is inaccurate as a benefit of API Gateway itself, since API Gateway can proxy to S3 but does not provide direct S3 file storage management as a core API management benefit. Option E is incorrect because automatic connection pooling for backend databases is handled by services like Amazon RDS Proxy, not API Gateway.

Exam trap

The trap here is that candidates confuse API Gateway's integration capabilities (e.g., proxying to S3 or RDS) with built-in backend features like caching or connection pooling, leading them to select options that describe backend functionality rather than API management features.

316
Multi-Selectmedium

A developer is designing a serverless application that processes orders. The order processing must be transactional: either all steps succeed or none. Which TWO AWS services can be combined to achieve this?

Select 2 answers
A.AWS Step Functions
B.Amazon SNS with filtering
C.Amazon SQS with FIFO queues
D.Amazon DynamoDB transactions
E.AWS Lambda with DLQ
AnswersA, D

AWS Step Functions is a powerful orchestration service that enables developers to define and execute complex, multi-step serverless workflows as state machines. It inherently supports error handling, retries, and parallel execution, making it ideal for coordinating multiple AWS services to achieve transactional-like behavior. By managing the state between steps and allowing for explicit success and failure paths, including compensating actions, Step Functions can ensure that a series of operations either completes entirely or is rolled back to a consistent state, effectively providing atomicity across distributed components.

Why this answer

AWS Step Functions is correct because it provides a state machine that can coordinate multiple AWS services (e.g., Lambda, DynamoDB) in a defined workflow. It supports error handling, retries, and a 'catch' mechanism to roll back or compensate for failed steps, enabling transactional order processing where all steps succeed or none do.

Exam trap

The trap here is that candidates often confuse message ordering or delivery guarantees (SQS FIFO) with transactional orchestration, failing to recognize that Step Functions is needed for coordinating multi-step rollback logic.

317
MCQmedium

A company uses Amazon CloudFront to distribute content from an S3 bucket. The content is static and rarely changes. The developer wants to reduce the load on the origin and improve performance for users. Which configuration change would achieve this?

A.Disable caching for the distribution.
B.Enable Lambda@Edge to process requests at edge locations.
C.Decrease the TTL (Time to Live) for the cache behavior.
D.Increase the TTL (Time to Live) for the cache behavior.
AnswerD

Increasing the TTL (Time to Live) for a cache behavior allows CloudFront to serve objects directly from its edge caches for a longer period before needing to revalidate or fetch them from the origin. This significantly improves the cache hit ratio, meaning more requests are served directly from the edge, which drastically reduces the number of requests reaching the origin server and lowers its operational load.

Why this answer

Increasing the TTL for the cache behavior tells CloudFront edge locations to retain cached copies of the static content for a longer period before re-validating with the origin S3 bucket. This reduces the number of requests that reach the origin, lowering load on the S3 bucket, and improves user performance by serving content directly from the edge cache more frequently.

Exam trap

The trap here is that candidates often confuse decreasing TTL with improving freshness, but for static, rarely changing content, a longer TTL reduces origin load and improves performance, not a shorter one.

How to eliminate wrong answers

Option A is wrong because disabling caching would force every request to go to the origin S3 bucket, increasing load and degrading performance, which is the opposite of the desired outcome. Option B is wrong because Lambda@Edge is used for custom logic at edge locations (e.g., authentication, header manipulation) and does not directly reduce origin load or improve caching for static, rarely changing content. Option C is wrong because decreasing the TTL causes CloudFront to re-validate content with the origin more often, increasing origin requests and latency, which contradicts the goal of reducing load and improving performance.

318
Multi-Selectmedium

A company is running a web application on EC2 instances behind an Application Load Balancer. The application experiences high latency during peak hours. A developer needs to improve performance. Which TWO actions should the developer take? (Choose TWO.)

Select 2 answers
A.Configure Auto Scaling to add more instances during peak hours.
B.Increase the ALB idle timeout.
C.Implement Amazon ElastiCache to cache frequently accessed data.
D.Use larger EC2 instance types.
E.Enable EBS optimization on the instances.
AnswersA, C

Configuring Auto Scaling allows the web application to dynamically adjust its capacity by launching additional EC2 instances when demand increases, such as during peak hours. This horizontal scaling approach ensures that the application maintains responsiveness and high availability by distributing the load across more resources, effectively preventing performance degradation and latency spikes. It automatically scales out to meet demand and scales in to optimize costs.

Why this answer

Option A is correct because configuring Auto Scaling to add more instances during peak hours horizontally scales the compute capacity behind the Application Load Balancer, distributing the increased request load across more targets and directly reducing the per-instance latency caused by peak traffic. Option C is correct because implementing Amazon ElastiCache (Redis or Memcached) offloads repeated reads of frequently accessed data from the backend instances and any database, cutting response times and reducing the load that contributes to high latency during peaks. Option B is not appropriate because increasing the ALB idle timeout only affects how long idle connections are kept open and does not improve application response latency.

Option D is not the best fit because vertically scaling with larger instance types is a single-instance change that does not address load distribution and is less elastic than Auto Scaling. Option E is incorrect because EBS optimization improves storage throughput/IOPS consistency for EBS-backed volumes, not the application's peak-hour latency driven by request load.

Exam trap

The trap here is that candidates often confuse vertical scaling (larger instances) with horizontal scaling (Auto Scaling), or think that increasing timeouts or enabling EBS optimization will fix application-level latency issues.

319
MCQmedium

A developer is building a RESTful API using Amazon API Gateway (REST API) and AWS Lambda. The API receives a large number of requests with duplicate payloads within a short time window. To improve performance and reduce costs, the developer wants to ensure that if the same request (based on a unique client ID) is sent within 5 minutes, the Lambda function is not invoked again, and the previously calculated response is returned. Which API Gateway feature should the developer use?

A.Enable API caching on the stage with a TTL of 300 seconds and configure the client ID as a cache key parameter.
B.Enable request validation to reject duplicate requests.
C.Configure a usage plan with a throttle rate to limit requests from each client.
D.Enable stage variables to store the previous response.
AnswerA

API Gateway's built-in caching mechanism is exclusively available for REST APIs, not HTTP APIs. While enabling caching on a stage with a specified TTL and using a client ID as a cache key parameter is a valid strategy for optimizing REST API performance and reducing backend load, this functionality is simply not supported for HTTP APIs. Therefore, this option cannot be implemented for the API type specified in the question, rendering it ineffective for the stated goal.

Why this answer

Amazon API Gateway (REST API) supports response caching at the stage level. By enabling API caching with a TTL of 300 seconds (5 minutes) and specifying the client ID as a cache key parameter, identical requests with the same client ID within the TTL will return the cached response without invoking the Lambda function. This reduces latency and cost.

Exam trap

Candidates might confuse this with HTTP APIs, which do not support native caching. The question specifies a REST API, making caching a valid feature. Also, ensure the cache key is configured correctly to avoid returning incorrect cached responses.

How to eliminate wrong answers

Option B is wrong because request validation in API Gateway checks for required headers, query strings, or body structure, but it does not detect or reject duplicate requests based on content or client ID. Option C is wrong because a usage plan with throttling limits the rate of requests per client (e.g., requests per second), but it does not cache responses or prevent Lambda invocation for duplicate requests within a time window; it simply rejects excess requests. Option D is wrong because stage variables are used to pass configuration values (like endpoint URLs) to integration functions at deployment time, not to store or return previous responses.

320
MCQmedium

A developer is building a serverless application that processes user-submitted images. The images are uploaded to an S3 bucket, which triggers an AWS Lambda function that creates a thumbnail and stores it in another S3 bucket. The developer notices that sometimes the Lambda function is invoked multiple times for a single image upload. What should the developer configure to ensure idempotent processing?

A.Enable S3 event notifications with a suffix filter.
B.Use an SQS queue to decouple S3 events.
C.Implement a DynamoDB table to track processed objects.
D.Increase the Lambda function's timeout.
AnswerC

Implementing a DynamoDB table to store identifiers of successfully processed objects (e.g., S3 object key and version ID) is an effective strategy for achieving idempotency. Before processing an S3 event, the Lambda function can attempt to write the object's unique identifier to the DynamoDB table with a `ConditionExpression` that ensures the item does not already exist. If the write fails because the item is already present, it indicates a duplicate event, and the function can safely exit without reprocessing, thus preventing unintended side effects.

Why this answer

S3 event notifications can occasionally deliver duplicate events (at-least-once semantics). By storing the unique object key (or ETag) in a DynamoDB table with a TTL, the Lambda function can check if the object has already been processed and skip duplicate invocations, ensuring idempotent processing.

Exam trap

The trap here is that candidates often assume SQS or filters guarantee exactly-once delivery, but AWS services like S3 and SQS both use at-least-once semantics, so idempotency must be implemented at the consumer level.

How to eliminate wrong answers

Option A is wrong because suffix filters only control which objects trigger notifications based on file extension; they do not prevent duplicate invocations for the same object. Option B is wrong because while an SQS queue can buffer events and reduce throttling, it does not eliminate duplicate events—S3 still sends at-least-once notifications to SQS, so duplicates can still occur. Option D is wrong because increasing the Lambda timeout only allows the function to run longer; it does not address the root cause of duplicate invocations or provide idempotency.

321
Multi-Selecthard

Which THREE actions can a developer take to improve the cold start latency of an AWS Lambda function?

Select 3 answers
A.Use a language runtime with faster startup time, such as Python or Node.js.
B.Place the Lambda function inside a VPC.
C.Enable provisioned concurrency for the function.
D.Increase the function's memory allocation.
E.Increase the function's timeout setting.
AnswersA, C, D

Python and Node.js runtimes generally exhibit significantly faster startup times compared to compiled languages like Java or .NET. This is primarily due to their lighter runtime environments and quicker code interpretation/JIT compilation processes. They require less time to load the runtime, initialize the execution environment, and parse/execute the initial function code, thereby reducing the duration of a cold start. This optimization directly minimizes the latency experienced by the end-user during the first invocation of an idle function.

Why this answer

Python and Node.js use interpreted runtimes with faster initialization times compared to compiled runtimes like Java or .NET. These runtimes have smaller binary sizes and lower startup overhead, reducing the time from invocation to execution start, which directly improves cold start latency.

Exam trap

The trap here is that candidates often confuse increasing timeout or placing functions in a VPC as performance optimizations, when in reality VPCs worsen cold starts and timeout only affects execution duration, not initialization speed.

322
MCQmedium

A developer is using the AWS Serverless Application Model (SAM) to define a serverless application with an API Gateway endpoint. The developer wants to enable API caching only in the development stage to speed up testing, but disable it in the production stage to ensure data freshness. What is the most efficient way to achieve this with SAM?

A.Use AWS SAM parameters with a condition to set CacheClusterEnabled based on the stage parameter.
B.Deploy two separate SAM templates, one for each stage.
C.Use a custom resource to toggle caching after deployment.
D.Enable caching globally and configure a usage plan with a quota for production.
AnswerA

AWS SAM parameters, combined with CloudFormation conditions, provide a robust mechanism to tailor resource configurations based on deployment-time inputs, such as a 'stage' parameter. By defining a condition that evaluates the 'stage' parameter (e.g., `Fn::Equals` 'prod'), the `CacheClusterEnabled` property can be conditionally set to `true` or `false` using `Fn::If`. This approach allows a single, consistent SAM template to manage multiple environments (e.g., dev, prod) without requiring manual modifications or separate template files, adhering to Infrastructure as Code best practices.

Why this answer

AWS SAM parameters allow you to define a stage parameter (e.g., 'dev' or 'prod') and use a condition to conditionally set the `CacheClusterEnabled` property on the `AWS::Serverless::Api` resource. This is the most efficient approach because it uses a single template and SAM's built-in intrinsic functions (like `Fn::Equals`) to toggle caching based on the deployment stage, avoiding separate templates or post-deployment custom resources.

Exam trap

The trap here is that candidates may think caching must be managed via usage plans or custom resources, overlooking SAM's ability to conditionally set API Gateway stage properties directly through parameters and conditions in a single template.

How to eliminate wrong answers

Option B is wrong because deploying two separate SAM templates duplicates infrastructure code and increases maintenance overhead, which is less efficient than using a single parameterized template. Option C is wrong because using a custom resource to toggle caching after deployment adds unnecessary complexity and latency, and SAM already supports conditional resource properties natively. Option D is wrong because enabling caching globally and using a usage plan with a quota does not disable caching for production; usage plans control throttling and API keys, not the API Gateway cache behavior, and caching would still be active in production, violating the requirement for data freshness.

323
Multi-Selectmedium

A developer is deploying a web application using AWS Elastic Beanstalk. The application needs to store session state. Which THREE services can be used for session state storage? (Choose THREE.)

Select 3 answers
A.Amazon ElastiCache for Redis
B.Amazon DynamoDB
C.Amazon S3
D.Amazon CloudFront
E.Amazon RDS
AnswersA, B, E

Amazon ElastiCache for Redis is an excellent choice for session storage due to its in-memory, key-value data store capabilities. It provides sub-millisecond latency and high throughput, which are critical for quickly retrieving and updating user session data with every request. Its ability to scale horizontally and its robust feature set make it ideal for managing transient, high-access application state efficiently.

Why this answer

Amazon ElastiCache for Redis (A) is correct because it is an in-memory data store that supports fast key-value session data with sub-millisecond latency and optional persistence, making it a standard choice for shared session state in Elastic Beanstalk applications. Amazon DynamoDB (B) is correct because it is a fully managed, highly available key-value NoSQL database that can store session tokens and attributes with consistent low-latency reads/writes at scale. Amazon RDS (E) is correct because a relational database such as MySQL, PostgreSQL, or SQL Server can persist session state in a table, and Elastic Beanstalk applications commonly use RDS for shared session storage.

Amazon S3 (C) is not appropriate because it is object storage with eventual consistency characteristics and higher latency, not designed for frequent small session reads/writes. Amazon CloudFront (D) is a content delivery network that caches HTTP content at edge locations and does not provide writable session state storage.

Exam trap

Candidates may mistakenly think Amazon S3 can be used for session state due to its general-purpose storage capabilities, but S3's high latency for small, frequent writes makes it unsuitable for session management. Additionally, some candidates might overlook RDS, but relational databases are a very common (though less performant) destination for session state, especially during lift-and-shift migrations.

324
MCQmedium

A developer is using AWS Lambda with an Amazon RDS MySQL database. The Lambda function frequently times out when connecting to the database. What is the MOST likely cause?

A.The Lambda function is not configured with enough memory
B.The Lambda function is not using a reserved concurrency limit
C.The Lambda function is not attached to the same VPC as the RDS instance
D.The Lambda function's execution role lacks RDS permissions
AnswerC

An Amazon RDS MySQL instance is deployed within a private Virtual Private Cloud (VPC) and is not publicly accessible by default, requiring private network access. For a Lambda function to connect to this private RDS instance, it must be configured to operate within the same VPC as the database, or a peered VPC, with appropriate security group rules allowing outbound traffic. Without this explicit VPC configuration, the Lambda function executes in the AWS managed network, lacking the necessary private network interface to reach the RDS endpoint directly, resulting in connection failures.

Why this answer

Lambda functions must be attached to the same VPC as the RDS instance to connect via a private IP address. Without VPC attachment, the Lambda function attempts to connect over the public internet, which can cause timeouts due to network latency, security group restrictions, or the RDS instance being configured as publicly inaccessible.

Exam trap

The trap here is that candidates often assume timeout issues are due to insufficient memory or IAM permissions, but the real cause is almost always a network connectivity problem when Lambda cannot reach the RDS instance inside a VPC.

How to eliminate wrong answers

Option A is wrong because increasing memory allocates more CPU and network bandwidth, but it does not resolve network connectivity issues like VPC misconfiguration. Option B is wrong because reserved concurrency limits the number of concurrent executions but does not affect individual function connection timeouts. Option D is wrong because IAM permissions control authorization to perform RDS API actions (e.g., creating snapshots), not network-level connectivity to the database; connection timeouts are a network issue, not an authorization issue.

325
MCQeasy

A developer is building a serverless application that needs to process messages from an Amazon SQS queue and store the results in an Amazon DynamoDB table. Which AWS service should the developer use to orchestrate the processing logic without managing servers?

A.Amazon Elastic Container Service (ECS) with Fargate
B.Amazon EC2 instances with a custom application
C.AWS Lambda
D.AWS Step Functions
AnswerC

AWS Lambda is the ideal serverless compute service for processing messages in an event-driven architecture. It automatically executes code in response to triggers, such as messages arriving in an SQS queue, without requiring any server provisioning or management. Lambda scales seamlessly with demand, offers a cost-effective pay-per-execution model, and integrates natively with other AWS services, making it perfectly suited for building highly scalable and resilient message processing components.

Why this answer

AWS Lambda is the correct choice because it is a serverless compute service that can be triggered by SQS messages via event source mappings, process each message, and write results to DynamoDB without provisioning or managing any servers. The developer simply uploads the processing code, and Lambda handles scaling, concurrency, and execution, making it ideal for this event-driven, serverless workflow.

Exam trap

The trap here is that candidates often confuse AWS Step Functions as a serverless orchestrator for simple tasks, but Step Functions is designed for coordinating multi-step workflows and state machines, not for directly processing individual SQS messages, which is a core Lambda use case.

How to eliminate wrong answers

Option A is wrong because Amazon ECS with Fargate, while serverless in terms of infrastructure management, still requires defining a container image, task definitions, and cluster configuration, which adds unnecessary overhead for a simple message-processing task that can be handled by a single function. Option B is wrong because Amazon EC2 instances require manual server provisioning, patching, scaling, and management, which violates the 'without managing servers' requirement of the question. Option D is wrong because AWS Step Functions is a state machine orchestration service designed to coordinate multiple AWS services and handle complex workflows, not to directly process individual SQS messages; using it here would introduce unnecessary complexity and cost compared to a direct Lambda trigger.

326
MCQeasy

A developer is writing a Lambda function that needs to access an Amazon RDS MySQL database. The function will be invoked frequently. What is the BEST practice for managing the database connection?

A.Close the database connection at the end of each invocation.
B.Open a new database connection inside the handler for each invocation.
C.Open the database connection outside the handler function and reuse it.
D.Use Amazon RDS Proxy to manage the connection pool.
AnswerD

While Amazon RDS Proxy is an excellent service for managing database connection pooling, multiplexing, and resilience for serverless applications, it is not the most direct or fundamental solution for how a developer should structure their Lambda function's code for efficient connection handling. RDS Proxy operates as an intermediary layer, abstracting connection management from the Lambda function itself. The question specifically asks about the developer's approach within the function, and reusing connections within the execution context is a more direct and immediate code-level optimization.

Why this answer

For Lambda functions accessing relational databases like Amazon RDS, the best practice is to use Amazon RDS Proxy. Because Lambda functions can scale rapidly to hundreds or thousands of concurrent executions, they can quickly exhaust the database's connection pool. RDS Proxy pools and shares these connections, improving scalability and application resilience.

While opening connections outside the handler (Option C) is a good general practice, it does not solve the connection exhaustion problem under high concurrency and frequent invocations.

Exam trap

Candidates often choose Option C because they remember the general Lambda rule of 'reusing connections outside the handler.' However, for relational databases (RDS), this approach still leads to connection exhaustion when Lambda scales. RDS Proxy (Option D) is the correct AWS-recommended architectural pattern for this scenario.

How to eliminate wrong answers

Option A is wrong because closing the database connection at the end of each invocation forces the next invocation to re-establish the connection, negating the benefit of connection reuse and increasing latency and database load. Option B is wrong because opening a new connection inside the handler for each invocation repeats the expensive connection setup (TCP handshake, SSL/TLS negotiation, MySQL authentication) on every call, which is inefficient for high-frequency invocations. Option D is wrong because while Amazon RDS Proxy can help manage connection pooling and reduce database load, it is not the best practice for the Lambda function itself; the question asks for managing the connection within the function, and RDS Proxy is an external service that adds complexity and cost, whereas reusing the connection outside the handler is simpler and more direct.

327
Multi-Selecteasy

A developer is using Amazon DynamoDB for a gaming leaderboard. The table has a sort key of 'score' (Number). The developer wants to retrieve the top 10 players. Which TWO operations can achieve this? (Choose TWO.)

Select 2 answers
A.TransactGetItems
B.Scan and sort results client-side, then take first 10
C.BatchGetItem
D.GetItem
E.Query with ScanIndexForward set to false and Limit set to 10
AnswersB, E

A Scan operation reads every single item in the entire DynamoDB table or a secondary index, which can then be sorted client-side by the score attribute in descending order, with the first 10 items taken. While this method technically yields the correct top 10 results, it is highly inefficient and expensive for large tables. It consumes significant read capacity units (RCUs) and network bandwidth by transferring all data, making it impractical for a production leaderboard.

Why this answer

Scanning all items and sorting them client-side by score descending gives the global top 10, regardless of partition keys. Option E is correct if the table is designed with a single partition key (e.g., a constant value like 'Leaderboard'), because a Query with ScanIndexForward=false and Limit=10 then retrieves the top 10 items from that partition efficiently. Options A, C, and D are incorrect because they cannot return the top 10 items sorted globally.

Exam trap

The pitfall is that candidates assume Query with ScanIndexForward=false and Limit=10 works globally across all partitions, but it only applies within a single partition key. However, if the table uses a constant partition key (common for leaderboards), it becomes a valid solution. Always consider the table design when evaluating Query vs.

Scan.

328
MCQhard

A company runs a critical web application on Amazon EC2 instances behind an Application Load Balancer. The application needs to authenticate users via an external OpenID Connect (OIDC) identity provider. The company wants to offload authentication to the load balancer and use IAM roles to access AWS resources. Which solution should the developer implement?

A.Configure the ALB target group to authenticate using the OIDC identity provider.
B.Use AWS Lambda@Edge to authenticate users at the edge.
C.Configure the ALB to use the OIDC identity provider for user authentication. Use the identity token to assume an IAM role via web identity federation.
D.Use Amazon Cognito user pools as the OIDC provider and integrate with ALB.
AnswerC

Application Load Balancers natively support authentication with OpenID Connect (OIDC) identity providers by configuring an `authenticate-oidc` action on a listener rule. After successful authentication, the ALB forwards the ID token to the backend application. The application can then use this OIDC identity token to securely assume an AWS IAM role via web identity federation, granting temporary, fine-grained permissions to access AWS resources without embedding long-lived credentials.

Why this answer

The Application Load Balancer (ALB) can directly authenticate users against an external OpenID Connect (OIDC) identity provider using its native OIDC authentication action. After successful authentication, the ALB passes the ID token to the backend application, which can then use the AWS Security Token Service (STS) AssumeRoleWithWebIdentity API to exchange the token for temporary AWS credentials, allowing the application to access AWS resources via an IAM role without managing long-term keys.

Exam trap

The trap here is that candidates confuse target group configuration with listener rule authentication actions, or assume that Cognito is required for any OIDC integration with ALB, when in fact ALB natively supports external OIDC providers directly.

How to eliminate wrong answers

Option A is wrong because ALB target groups do not handle authentication; authentication is configured at the listener rule level, not on the target group. Option B is wrong because Lambda@Edge is designed for content delivery and request/response manipulation at CloudFront edge locations, not for offloading OIDC authentication directly to an ALB or for assuming IAM roles via web identity federation. Option D is wrong because while Amazon Cognito can act as an OIDC provider and integrate with ALB, the question specifies an external OIDC provider, and using Cognito would introduce an unnecessary intermediary; the ALB supports direct integration with any OIDC-compliant identity provider without requiring Cognito.

329
MCQmedium

A developer is building a RESTful API using Amazon API Gateway and AWS Lambda. The API needs to support custom domain names with SSL/TLS certificates. The developer has created the custom domain name in API Gateway and uploaded the certificate to AWS Certificate Manager (ACM) in the same region. However, when accessing the custom domain, users get an SSL error. What is the most likely cause?

A.The certificate was not issued by a trusted certificate authority.
B.The custom domain name's DNS record does not point to API Gateway's regional domain name.
C.The API Gateway API is not deployed to a stage that is mapped to the custom domain name.
D.The certificate is in the wrong region relative to the API Gateway regional endpoint.
AnswerB

For a custom domain to function with API Gateway, its DNS record (typically a CNAME or an ALIAS record in Route 53) must correctly resolve to the API Gateway's regional endpoint domain name. If the DNS record is misconfigured or missing, client requests will not reach the API Gateway endpoint associated with the custom domain. Consequently, the server presenting the certificate (which would be the API Gateway) cannot be found at the requested custom domain, leading to an SSL handshake failure as the client cannot establish a secure connection with the intended server.

Why this answer

The most likely cause is that the custom domain name's DNS record does not point to API Gateway's regional domain name. When using a custom domain name with API Gateway, you must create a DNS record (typically a CNAME or A record using Route 53 alias) that maps your custom domain to the API Gateway-generated regional domain name (e.g., d-xxxxx.execute-api.region.amazonaws.com). Without this correct DNS mapping, the SSL/TLS handshake fails because the certificate presented by API Gateway does not match the domain name the client is connecting to, resulting in an SSL error.

Exam trap

The trap here is that candidates often confuse SSL errors with API configuration issues like missing stage mappings or incorrect certificate authorities, but SSL errors occur at the transport layer due to DNS misconfiguration or certificate domain mismatch, not at the application layer.

How to eliminate wrong answers

Option A is wrong because AWS Certificate Manager (ACM) only issues certificates that are trusted by major browsers and operating systems; if ACM issued the certificate, it is automatically from a trusted CA, so this is not the cause. Option C is wrong because while the API must be deployed to a stage and the stage must be mapped to the custom domain name for the API to respond, an SSL error occurs at the TLS handshake level before any API routing happens; a missing stage mapping would cause a 404 or 403 error, not an SSL error. Option D is wrong because the developer created the custom domain name in API Gateway and uploaded the certificate to ACM in the same region, so the region mismatch is not the issue; the certificate must be in the same region as the API Gateway regional endpoint, which it is.

330
MCQeasy

A developer needs to store application configuration that can be accessed by multiple microservices running on Amazon ECS. The configuration must be encrypted at rest and automatically rotate secrets. Which AWS service should be used?

A.AWS Systems Manager Parameter Store
B.AWS CloudFormation
C.Amazon S3
D.AWS Secrets Manager
AnswerD

AWS Secrets Manager is specifically engineered for managing sensitive credentials such as database passwords, API keys, and other secrets that require robust security and lifecycle management. Its core features include automatic rotation, fine-grained access control, and auditing, which are critical for secrets but often overkill for general application configuration. While technically capable of storing configuration, its higher cost and specialized feature set make it an inefficient choice for non-secret application parameters.

Why this answer

AWS Secrets Manager is the correct choice because it is specifically designed to protect secrets (such as database credentials, API keys, and OAuth tokens) and features built-in, automatic rotation of secrets using AWS Lambda. While AWS Systems Manager Parameter Store can store encrypted configuration data (using SecureString), it does not offer native automatic rotation capabilities; implementing rotation in Parameter Store requires custom integration and code.

Exam trap

Candidates often confuse AWS Systems Manager Parameter Store and AWS Secrets Manager. While both can store encrypted data, only AWS Secrets Manager provides native, automatic rotation of secrets. If the exam question mentions 'automatically rotate secrets' as a requirement, AWS Secrets Manager is almost always the correct choice.

How to eliminate wrong answers

Option B (AWS CloudFormation) is wrong because it is an infrastructure-as-code service for provisioning resources, not a runtime configuration store; it cannot dynamically serve configuration to running microservices or rotate secrets automatically. Option C (Amazon S3) is wrong because while it can store encrypted objects, it lacks native secret rotation capabilities and is not designed for low-latency, parameter-style access from ECS tasks without additional client logic. Option D (AWS Secrets Manager) is wrong because although it supports automatic secret rotation and encryption, it is specifically designed for managing secrets like database credentials, not general application configuration; the question asks for storing 'application configuration' that must be rotated, and Parameter Store is the more appropriate service for configuration data with optional rotation via integration.

331
MCQhard

A DynamoDB table uses partition key customerId. One enterprise customer generates most traffic and is throttled while the table has unused capacity elsewhere. What design change best addresses the hot partition?

A.Enable point-in-time recovery
B.Reduce item size by removing attributes
C.Use strongly consistent reads only
D.Add write sharding or redesign the partition key to distribute that customer's workload
AnswerD

A hot partition occurs when a single partition key value receives disproportionately high read or write traffic, leading to throttling. To mitigate this, one can implement write sharding by appending a random or calculated suffix to the `customerid` (e.g., `customerid-001`, `customerid-002`), effectively distributing that single customer's operations across multiple logical partitions. Alternatively, redesigning the partition key entirely to include a more granular attribute alongside `customerid` can achieve similar workload distribution.

Why this answer

The hot partition is caused by a single customerId receiving a disproportionate amount of traffic, exceeding the 3000 RCU or 1000 WCU per partition limit. By adding write sharding (e.g., appending a random suffix to the partition key) or redesigning the partition key to include a more granular attribute, you distribute that customer's writes across multiple partitions, eliminating the bottleneck and utilizing the table's unused capacity.

Exam trap

The trap here is that candidates mistakenly believe reducing item size or changing read consistency can resolve a hot partition, when only redistributing the partition key's workload addresses the underlying throughput imbalance.

How to eliminate wrong answers

Option A is wrong because point-in-time recovery (PITR) enables continuous backups and restores to any point within the last 35 days; it does not affect request distribution or throttling. Option B is wrong because reducing item size can lower consumed capacity per operation but does not change how requests are distributed across partitions; the hot partition remains throttled if the same customerId still receives high traffic. Option C is wrong because strongly consistent reads consume twice the RCU of eventually consistent reads and do not alter partition key distribution; they would actually increase throttling risk on the hot partition.

332
MCQeasy

A developer wants to trigger an AWS Lambda function every time a new object is created in an Amazon S3 bucket. Which S3 event notification configuration should be used?

A.s3:ObjectCreated:*
B.s3:ObjectRestore:*
C.s3:ReducedRedundancyLostObject:*
D.s3:ObjectRemoved:*
AnswerA

This event notification type, `s3:ObjectCreated:*`, is a wildcard that encompasses all actions resulting in a new object being stored in an S3 bucket. It includes specific events like `s3:ObjectCreated:Put`, `s3:ObjectCreated:Post`, `s3:ObjectCreated:Copy`, and `s3:ObjectCreated:CompleteMultipartUpload`. This makes it the most comprehensive and appropriate choice for triggering a Lambda function whenever any new file is successfully added to S3, regardless of the specific upload method used.

Why this answer

The `s3:ObjectCreated:*` event type captures all object creation events in an S3 bucket, including PUT, POST, COPY, and multipart upload completions. This is the appropriate event notification to trigger an AWS Lambda function when a new object is created.

Exam trap

The trap here is that candidates might confuse `s3:ObjectCreated:*` with `s3:ObjectRemoved:*` or `s3:ObjectRestore:*`, thinking any object state change triggers the function, but only creation events are relevant for the 'new object' requirement.

How to eliminate wrong answers

Option B is wrong because `s3:ObjectRestore:*` is used for S3 Glacier or S3 Deep Archive restore lifecycle events, not for new object creation. Option C is wrong because `s3:ReducedRedundancyLostObject:*` is a deprecated event that only fires when an object stored with Reduced Redundancy Storage (RRS) is lost, which is unrelated to new object creation. Option D is wrong because `s3:ObjectRemoved:*` is triggered when objects are deleted (e.g., via DELETE or lifecycle expiration), not when they are created.

333
Multi-Selectmedium

A developer is designing a messaging system where orders are placed into an SQS queue and processed by a Lambda function. The developer wants to ensure that failed messages are not lost and can be analyzed later. Which TWO steps should the developer take? (Choose 2.)

Select 2 answers
A.Configure a dead-letter queue (DLQ) for the SQS queue.
B.Enable Lambda function retries on failure.
C.Set the redrive policy to move messages to the DLQ after a specified number of receive attempts.
D.Increase the visibility timeout of the SQS queue.
E.Set up a CloudWatch alarm to monitor the queue depth.
AnswersA, C

A dead-letter queue (DLQ) is a standard SQS queue that receives messages from a source queue after they have failed to be processed successfully a specified number of times. Configuring a DLQ prevents messages from being lost due to repeated processing failures, allowing for later inspection, debugging, or manual reprocessing. This mechanism is crucial for ensuring message durability and reliability in a distributed messaging system, isolating problematic messages.

Why this answer

Configuring a dead-letter queue (DLQ) for the SQS queue ensures that messages that cannot be processed successfully after a specified number of attempts are moved to a separate queue. This prevents message loss and allows the developer to analyze the failed messages later, fulfilling the requirement to not lose failed messages and to enable analysis.

Exam trap

The trap here is that candidates often confuse Lambda retries (which only re-invoke the function) with the SQS DLQ mechanism, failing to realize that without a DLQ, messages that exhaust all retries are silently deleted from the queue and permanently lost.

334
Multi-Selecteasy

A developer is using Amazon DynamoDB as a data store for a serverless application. The application requires strongly consistent reads and must be able to recover from failures. Which THREE measures should the developer implement? (Choose THREE.)

Select 2 answers
A.Use the ConsistentRead parameter set to true in GetItem and Query operations.
B.Use DynamoDB read replicas to offload read traffic.
C.Configure DynamoDB global tables for multi-region replication.
D.Enable DynamoDB Streams to capture changes.
E.Implement DAX (DynamoDB Accelerator) for caching.
AnswersA, C

Setting ConsistentRead to true forces DynamoDB to return the most up-to-date data by reading from the leader node, satisfying the strong consistency requirement for GetItem and Query. Without it, reads may return stale replicas, which the application cannot tolerate.

Why this answer

Option A is correct because setting ConsistentRead to true on GetItem, Query, and Scan forces a strongly consistent read that returns the most up-to-date data instead of a possibly stale eventually consistent result. Option C is correct because DynamoDB global tables provide multi-region, active-active replication, allowing the application to continue serving reads and writes from another Region if one Region fails, which directly supports failure recovery. Option D is incorrect because DynamoDB Streams is a change-data-capture feature that records item-level changes for event-driven processing, replication, or auditing; it does not itself provide failure recovery or strongly consistent reads.

Option B is incorrect because DynamoDB does not offer native read replicas as a standalone feature; read scaling is achieved through partitions, global tables, or DAX. Option E is incorrect because DAX is an in-memory write-through cache that serves eventually consistent reads by default and does not provide strongly consistent reads or cross-Region failure recovery.

Exam trap

The trap is confusing DAX (performance enhancement) with a recovery mechanism, or assuming DynamoDB has read replicas like RDS. Avoid selecting options that only improve performance or are not available for DynamoDB.

335
Multi-Selecthard

Which THREE AWS services are commonly used together to build a serverless event-driven architecture that processes real-time streaming data? (Choose three.)

Select 3 answers
A.Amazon Kinesis Data Streams
B.AWS Lambda
C.Amazon DynamoDB
D.Amazon SQS
E.Amazon Redshift
AnswersA, B, C

Amazon Kinesis Data Streams is a highly scalable and durable real-time data streaming service. It can continuously capture gigabytes of data per second from hundreds of thousands of sources, such as website clickstreams, IoT device data, and financial transactions. This service acts as the entry point for real-time data pipelines, providing a persistent, ordered, and replayable stream of records for downstream processing.

Why this answer

Amazon Kinesis Data Streams (A) is correct because it ingests and buffers real-time streaming data at scale, serving as the event source for downstream serverless processing. AWS Lambda (B) is correct because it provides serverless compute that can be triggered by Kinesis stream records via event source mappings, enabling event-driven processing without managing servers. Amazon DynamoDB (C) is correct because it is a fully managed, serverless NoSQL database commonly used as the sink to store processed streaming results, and DynamoDB Streams can further propagate events.

Amazon SQS (D) is not selected because it is a message queue for decoupling components, not a real-time streaming data service, and it is not one of the three services typically combined for streaming ingestion and processing in this scenario. Amazon Redshift (E) is not selected because it is a data warehouse designed for analytical queries on batch-loaded data, not for real-time serverless stream processing.

Exam trap

The trap here is that candidates often confuse Amazon SQS with Kinesis Data Streams, but SQS is a pull-based queue for decoupled messaging, not a streaming data platform with ordered, replayable records.

336
MCQeasy

A developer needs to store application configuration data, such as database connection strings and API keys, for a microservices application running on Amazon ECS. The configuration must be encrypted at rest and easily auditable. Which AWS service should the developer use?

A.AWS Secrets Manager.
B.Amazon S3 with server-side encryption.
C.AWS Systems Manager Parameter Store.
D.Amazon DynamoDB with encryption at rest.
AnswerC

AWS Systems Manager Parameter Store is purpose-built for securely storing and managing application configuration data, including both plain-text and encrypted parameters. It offers hierarchical organization, automatic versioning of parameter changes, and seamless integration with AWS Key Management Service (KMS) for encryption. Its ability to retrieve parameters by name and integration with AWS CloudTrail for auditing all access and modifications makes it the ideal, cost-effective, and operationally simple choice for this use case.

Why this answer

AWS Systems Manager Parameter Store is the correct choice because it is designed to store application configuration data like database connection strings and API keys, integrates natively with Amazon ECS for secure parameter retrieval, and supports encryption at rest using AWS KMS. It also provides built-in auditing through AWS CloudTrail, which logs all API calls to the Parameter Store, meeting the auditability requirement.

Exam trap

The trap here is that candidates often confuse AWS Secrets Manager with Systems Manager Parameter Store, but Secrets Manager is specifically for secrets requiring automatic rotation, while Parameter Store is the appropriate choice for general configuration data that needs encryption and auditing without rotation.

How to eliminate wrong answers

Option A is wrong because AWS Secrets Manager is optimized for managing secrets with automatic rotation, which is overkill for general configuration data and incurs additional cost per secret; the question does not require rotation. Option B is wrong because Amazon S3 with server-side encryption can store configuration data but lacks native integration with ECS for secure, low-latency parameter retrieval and does not provide the same level of auditability via CloudTrail for individual parameter access without additional configuration. Option D is wrong because Amazon DynamoDB with encryption at rest is a NoSQL database designed for high-scale application data, not for storing simple configuration parameters, and it requires custom code to manage access control and auditing, adding unnecessary complexity.

337
MCQhard

A developer is deploying a microservices architecture on Amazon ECS with Fargate. Each service needs to store sensitive configuration data such as database passwords. The developer wants to avoid hardcoding secrets in the application code. Which approach should the developer use?

A.Store the secrets in an Amazon S3 bucket and use a pre-signed URL to download them at startup.
B.Define the secrets as environment variables in the ECS task definition.
C.Encrypt the secrets using AWS KMS and store the encrypted blob in a configuration file within the Docker image.
D.Store the secrets in AWS Systems Manager Parameter Store or AWS Secrets Manager and reference them in the ECS task definition using the 'secrets' parameter.
AnswerD

This is the most secure and recommended approach for managing secrets in ECS. AWS Systems Manager Parameter Store (especially `SecureString` parameters) and AWS Secrets Manager are purpose-built services for securely storing and managing sensitive data. By referencing these services in the ECS task definition's `secrets` parameter, ECS automatically retrieves and injects the secrets into the container's environment at runtime, leveraging the task's IAM role for secure, granular access. This ensures secrets are never hardcoded, are not visible in task definitions or logs, and can be rotated independently of application deployments.

Why this answer

AWS Systems Manager Parameter Store and AWS Secrets Manager are purpose-built services for securely storing and managing sensitive configuration data. By referencing secrets via the `secrets` parameter in the ECS task definition, the secrets are injected into the container at runtime without being exposed in the application code, task definition plaintext, or Docker image. This approach integrates natively with ECS Fargate and supports automatic rotation of secrets.

Exam trap

The trap here is that candidates often choose Option B (environment variables in the task definition) because it seems simple and works in development, but they overlook that the task definition is stored in plaintext and accessible via the ECS API, making it insecure for production secrets.

How to eliminate wrong answers

Option A is wrong because storing secrets in an S3 bucket with a pre-signed URL introduces a long-lived URL that can be intercepted or leaked, and it does not provide native secret rotation or fine-grained access control compared to AWS Secrets Manager. Option B is wrong because defining secrets as environment variables in the ECS task definition stores them in plaintext within the task definition, which can be viewed by anyone with access to the ECS API or console, violating security best practices. Option C is wrong because encrypting secrets with KMS and storing the encrypted blob in a Docker image embeds the encrypted data in the image, making it difficult to rotate secrets without rebuilding the image, and the decryption key must be managed separately, increasing complexity and risk.

338
MCQeasy

A developer is writing code to upload an object to an Amazon S3 bucket. The object is 200 MB in size. Which AWS SDK method should the developer use to perform this upload?

A.Enable S3 Transfer Acceleration and use the PutObject API.
B.Use the PutObject API operation.
C.Use the multipart upload API.
D.Use a pre-signed URL and upload using HTTP PUT.
AnswerC

The S3 multipart upload API is the recommended and most robust method for uploading large objects to Amazon S3, particularly those exceeding 100 MB, and is mandatory for objects larger than 5 GB. This API breaks the object into smaller, manageable parts, which can be uploaded independently, in parallel, and even out of order. This approach significantly enhances upload speed, provides resilience against network failures (only failed parts need re-uploading), and allows for pausing and resuming uploads.

Why this answer

Objects larger than 100 MB should be uploaded using the multipart upload API to improve throughput and provide resilience against network failures. The multipart upload API allows the 200 MB object to be split into parts, uploaded in parallel, and then assembled, which is more efficient and reliable than a single PutObject operation for objects over 5 GB or for large objects in general.

Exam trap

The trap here is that candidates assume the PutObject API is sufficient for any object under 5 GB, but the AWS SDK best practice and the exam emphasize using multipart upload for objects over 100 MB to ensure reliability and performance.

How to eliminate wrong answers

Option A is wrong because S3 Transfer Acceleration is a feature that speeds up uploads over long distances using edge locations, but it does not replace the need for multipart upload for large objects; the PutObject API still has a 5 GB limit and is not recommended for objects over 100 MB. Option B is wrong because the PutObject API operation is designed for objects up to 5 GB, but for a 200 MB object, using a single PutObject call is less reliable and efficient than multipart upload due to potential network interruptions and lack of parallel uploads. Option D is wrong because a pre-signed URL grants temporary access for an HTTP PUT upload, but it still uses the PutObject API under the hood, which is not optimal for a 200 MB object; multipart upload is the recommended approach for objects over 100 MB.

339
MCQhard

A developer is using AWS X-Ray to trace requests through a microservices application. The application consists of several AWS Lambda functions that call each other and Amazon DynamoDB. The developer notices that some traces are incomplete and missing segments for downstream calls. What is the MOST likely cause?

A.The downstream DynamoDB table does not have X-Ray tracing enabled.
B.The Lambda functions do not have the X-Ray SDK imported.
C.The X-Ray daemon is not running on the Lambda execution environment.
D.The X-Ray sampling rate is set too low.
AnswerB

This is correct. If the Lambda functions do not import the X-Ray SDK, they cannot create segments or subsegments for downstream calls, leading to incomplete traces.

Why this answer

The Lambda functions need to import the X-Ray SDK to create subsegments for downstream calls and propagate the trace header. Without the SDK, traces will be missing segments for DynamoDB calls. DynamoDB does not have a per-table X-Ray tracing setting; tracing is achieved by instrumenting the client in the calling code.

Exam trap

The trap is that candidates often think DynamoDB tables have an X-Ray tracing toggle, but in reality, X-Ray tracing for DynamoDB is done by instrumenting the client with the X-Ray SDK. The most common cause of missing segments is failing to import and use the X-Ray SDK in Lambda functions.

How to eliminate wrong answers

Option B is wrong because the Lambda functions do not need the X-Ray SDK imported to send trace data; the X-Ray daemon automatically captures segments for Lambda invocations and downstream calls if the service supports it. Option C is wrong because the X-Ray daemon is already running in the Lambda execution environment by default when X-Ray tracing is enabled on the Lambda function. Option D is wrong because a low sampling rate would reduce the number of traces captured, not cause incomplete traces with missing segments for downstream calls.

340
MCQmedium

A developer is using Amazon API Gateway with a Lambda authorizer to control access to an API. The authorizer function needs to decode a JWT token from the request header and return an IAM policy. Which type of Lambda authorizer should be used?

A.TOKEN authorizer with the token passed in the Authorization header.
B.REQUEST authorizer with the token in a custom header.
C.Use Amazon Cognito User Pools as the authorizer.
D.Use a resource policy to allow or deny access based on the JWT token.
AnswerA

A TOKEN authorizer is specifically designed to receive a single authorization token, typically a JWT, from a designated header like `Authorization`. It passes this token directly to a Lambda function which then decodes and validates it, returning an IAM policy that grants or denies access to API resources. This streamlined approach is ideal for scenarios focused solely on token-based authentication, simplifying the Lambda's input processing by providing just the raw token string.

Why this answer

A TOKEN authorizer is designed to receive a JWT or OAuth token in the Authorization header and pass it directly to the Lambda function for validation. The Lambda function then decodes the token and returns an IAM policy document to allow or deny the API request. This is the correct choice because the question explicitly states the token is in the request header and needs to be decoded, which matches the TOKEN authorizer's behavior of forwarding the raw token value.

Exam trap

The trap here is that candidates confuse the TOKEN authorizer (which passes only the token) with the REQUEST authorizer (which passes the full request), assuming that decoding a JWT requires access to other request parameters, when in fact the token alone is sufficient for validation.

How to eliminate wrong answers

Option B is wrong because a REQUEST authorizer passes the entire request context (headers, query parameters, path parameters) to the Lambda function, which is unnecessary overhead when only the JWT token from a header is needed; it also requires more complex parsing logic. Option C is wrong because Amazon Cognito User Pools are a managed identity service that handles JWT verification natively, not a Lambda authorizer; using them would bypass the requirement for a custom Lambda function to decode the token. Option D is wrong because resource policies control access based on IP addresses, VPCs, or AWS accounts, not on the contents of a JWT token; they cannot decode or validate token claims.

341
MCQeasy

A developer is building a serverless application using AWS Lambda. The function needs to access a DynamoDB table and write logs to Amazon CloudWatch. What is the minimum set of IAM permissions the Lambda execution role must have?

A.dynamodb:PutItem, logs:CreateLogGroup, logs:CreateLogStream, logs:PutLogEvents
B.logs:CreateLogGroup, logs:CreateLogStream, logs:PutLogEvents
C.dynamodb:*, logs:PutLogEvents
D.dynamodb:GetItem, dynamodb:PutItem, logs:PutLogEvents
AnswerA

This option provides the precise set of permissions required for a serverless application, such as an AWS Lambda function, to operate effectively. `dynamodb:PutItem` enables the function to write data to a DynamoDB table, fulfilling its primary data interaction requirement. Concurrently, `logs:CreateLogGroup`, `logs:CreateLogStream`, and `logs:PutLogEvents` grant the necessary capabilities for the Lambda function to establish its dedicated log group and stream, then continuously publish its execution logs to CloudWatch, ensuring comprehensive operational visibility. This adheres to the principle of least privilege by granting only essential actions.

Why this answer

The Lambda execution role must include `dynamodb:PutItem` to write to the DynamoDB table, and the three `logs:` permissions (`CreateLogGroup`, `CreateLogStream`, `PutLogEvents`) are required for Lambda to create log groups/streams and send log events to CloudWatch Logs. This is the minimum set that satisfies both requirements without granting unnecessary privileges.

Exam trap

The trap here is that candidates often forget that Lambda requires both `logs:CreateLogGroup` and `logs:CreateLogStream` (not just `logs:PutLogEvents`) to set up CloudWatch logging, or they assume `dynamodb:GetItem` is needed for writing, leading them to choose Option D.

How to eliminate wrong answers

Option B is wrong because it omits `dynamodb:PutItem`, which is essential for writing to the DynamoDB table; without it, the function will fail with an access denied error. Option C is wrong because `dynamodb:*` grants all DynamoDB actions (including delete, scan, etc.), which violates the principle of least privilege and is not the minimum set. Option D is wrong because it includes `dynamodb:GetItem` (unnecessary for writing) and omits `logs:CreateLogGroup` and `logs:CreateLogStream`, which are required for Lambda to initialize CloudWatch log streams; without them, the function cannot write logs.

342
Multi-Selectmedium

A developer is designing a serverless application that uses Amazon API Gateway and AWS Lambda. The API receives a high volume of requests, and the developer needs to cache responses to reduce latency and cost. Which TWO actions should the developer take? (Choose TWO.)

Select 2 answers
A.Use DynamoDB Accelerator (DAX) to cache Lambda responses.
B.Use ElastiCache for Redis to store frequently accessed responses.
C.Use Amazon CloudFront in front of API Gateway to cache responses.
D.Enable API Gateway caching and set a TTL for the cache.
E.Configure the Lambda function to return cache-control headers in the response.
AnswersC, D

CloudFront caches at the edge location level, but API Gateway’s native caching operates at the API stage level, which is the specific requirement for reducing latency and cost within the API Gateway service itself. This option is tempting because CloudFront is commonly used to accelerate content delivery and cache static assets for web applications, and it would be the correct choice if the goal were to offload requests from the origin for a globally distributed user base rather than caching API responses at the API Gateway stage.

Why this answer

Option C is correct because Amazon CloudFront can be deployed in front of API Gateway as a CDN, caching responses at edge locations to reduce latency and offload requests from the API, which lowers Lambda invocations and cost. Option D is correct because API Gateway has a built-in caching feature that can be enabled per stage or method, and setting a TTL controls how long responses are cached, directly reducing backend calls and latency. Option A is incorrect because DAX is a caching layer for DynamoDB, not for API Gateway or Lambda responses.

Option B is incorrect because ElastiCache for Redis would require custom application logic to read/write the cache and is not a native API Gateway caching mechanism. Option E is incorrect because returning cache-control headers from Lambda does not by itself enable caching in API Gateway; caching must be explicitly configured on the API Gateway stage or method.

Exam trap

Candidates often miss that CloudFront (Option C) can be placed in front of API Gateway to act as a highly cost-effective cache. They might incorrectly choose Option E, thinking that returning `Cache-Control` headers from Lambda automatically enables caching, but without a caching proxy like CloudFront, those headers only affect client-side (browser) caching and do not protect the backend from high-volume concurrent requests from different users.

343
MCQeasy

A developer wants to store application logs in Amazon S3 with automatic transition to Glacier after 30 days and deletion after 365 days. Which S3 feature should be used?

A.S3 Lifecycle configuration
B.S3 Object Lock
C.S3 Replication
D.S3 Event Notifications
AnswerA

S3 Lifecycle configuration is the correct choice because it allows developers to define rules for automatically transitioning objects between different S3 storage classes (e.g., S3 Standard to S3 Standard-IA, Glacier, or Glacier Deep Archive) based on their age or access patterns. This is ideal for application logs, which typically become less frequently accessed over time but still require retention, enabling significant cost savings by moving them to progressively colder storage tiers. Furthermore, lifecycle policies can also be configured to automatically expire and permanently delete objects after a specified period, ensuring compliance and managing storage footprint efficiently.

Why this answer

S3 Lifecycle configuration is the correct feature because it allows you to define rules that automatically transition objects to colder storage classes like Glacier after a specified number of days (30) and permanently delete them after a longer period (365). This directly matches the requirement for time-based storage tiering and deletion without manual intervention.

Exam trap

The trap here is that candidates confuse S3 Lifecycle policies with S3 Event Notifications, thinking event-driven triggers can handle time-based transitions, but Lifecycle policies are the only native S3 feature that automates storage class transitions and deletions based on object age.

How to eliminate wrong answers

Option B is wrong because S3 Object Lock is designed to prevent objects from being deleted or overwritten for a fixed retention period, not to automate storage class transitions or scheduled deletions. Option C is wrong because S3 Replication asynchronously copies objects to another bucket for redundancy or compliance, but it does not manage lifecycle transitions or deletion schedules. Option D is wrong because S3 Event Notifications trigger actions (e.g., Lambda, SQS) on object events like PUT or DELETE, but they cannot enforce time-based transitions to Glacier or automatic deletion after a set number of days.

344
MCQhard

An organization uses AWS CodeBuild to run tests for a Node.js application. The build environment is Linux. The buildspec.yml includes a pre_build phase that runs 'npm install'. Occasionally, the build fails with an error 'npm ERR! code EINTEGRITY'. The developer wants to resolve this issue without compromising security. Which action should be taken?

A.Create a separate CodeBuild project to run npm install.
B.Add 'npm cache verify' to the pre_build phase before 'npm install'.
C.Add 'npm config set registry http://registry.npmjs.org/' to use HTTP.
D.Use 'npm install --prefer-offline' to avoid fetching from registry.
AnswerB

Adding 'npm cache verify' to the `pre_build` phase before 'npm install' is the correct solution because it directly addresses the cause of an 'EINTEGRITY' error. This command systematically checks the integrity of all cached packages, identifying and repairing any corrupted or incomplete entries. By ensuring the npm cache is clean and valid, subsequent 'npm install' commands will operate with correct package data, resolving the integrity mismatch without compromising security or requiring a full cache clear.

Why this answer

The EINTEGRITY error occurs when npm's local cache contains corrupted or mismatched package data, causing integrity checks to fail. Running 'npm cache verify' in the pre_build phase validates the cache, removes corrupted entries, and garbage collects unnecessary data, ensuring subsequent 'npm install' operations use a clean cache. This resolves the issue without disabling security features like integrity checking or switching to insecure HTTP.

Exam trap

DVA-C02 often tests the misconception that EINTEGRITY errors are network-related and can be fixed by changing registry protocols or offline flags, when the actual cause is local cache corruption.

How to eliminate wrong answers

Option A is wrong because creating a separate CodeBuild project does not address the root cause—cache corruption—and adds unnecessary complexity. Option C is wrong because switching to HTTP disables TLS encryption, compromising security and violating best practices; the error is not caused by HTTPS. Option D is wrong because '--prefer-offline' still uses the corrupted cache and may fail integrity checks; it does not repair the cache and could mask the issue while potentially using stale packages.

345
MCQeasy

A developer is creating an AWS Lambda function that needs to access files from an Amazon EFS file system. The Lambda function must be configured to access the VPC. Which of the following is required to allow the Lambda function to mount the EFS file system?

A.The Lambda function must have the AWSLambdaVPCAccessExecutionRole managed policy attached.
B.The Lambda function must be in the same Availability Zone as the EFS mount target.
C.The Lambda function must have the AmazonElasticFileSystemClientReadWriteAccess managed policy attached.
D.The Lambda function must have the efs:MountFileSystem permission in its execution role.
AnswerA

The AWSLambdaVPCAccessExecutionRole managed policy is essential because it grants the necessary IAM permissions for Lambda to create, describe, and delete Elastic Network Interfaces (ENIs) within the specified VPC subnets. When a Lambda function is configured to access resources in a VPC, AWS Lambda provisions these ENIs to establish network connectivity, allowing the function to communicate with private resources like EFS file systems. Without these permissions, Lambda cannot integrate into the VPC and therefore cannot reach EFS.

Why this answer

The AWSLambdaVPCAccessExecutionRole managed policy provides the necessary permissions for Lambda to manage elastic network interfaces (ENIs) in a VPC, which is required for Lambda to connect to an EFS file system via mount targets. Without this policy, the Lambda function cannot create or manage the ENI needed to route traffic to the EFS mount target within the VPC.

Exam trap

The trap here is that candidates confuse the VPC networking permissions required for Lambda to mount EFS (AWSLambdaVPCAccessExecutionRole) with EFS-specific API permissions (AmazonElasticFileSystemClientReadWriteAccess) or a nonexistent efs:MountFileSystem action, leading them to select the wrong policy or permission.

How to eliminate wrong answers

Option B is wrong because Lambda can access EFS mount targets in any Availability Zone within the same VPC; it does not need to be in the same AZ as the mount target, as Lambda uses ENIs in the VPC subnets to reach the mount target across AZs. Option C is wrong because the AmazonElasticFileSystemClientReadWriteAccess policy grants permissions to EFS API operations (e.g., CreateFileSystem, DescribeMountTargets) but does not include the specific efs:MountFileSystem permission or the VPC networking permissions required for Lambda to mount the file system. Option D is wrong because the efs:MountFileSystem permission is not a valid IAM action; EFS mounting is controlled by network connectivity (VPC configuration) and the execution role must include permissions for EC2 ENI management (ec2:CreateNetworkInterface, etc.), not a direct EFS mount action.

346
MCQeasy

A company stores sensitive user data in an S3 bucket. The security team requires that all data be encrypted at rest using a customer-managed KMS key. The bucket already has default encryption configured with SSE-S3. What is the MINIMUM change needed to meet the requirement?

A.Change the default encryption of the bucket to SSE-KMS with the desired KMS key.
B.Add an object-level encryption setting to each object after upload.
C.Enable S3 Bucket Keys on the bucket.
D.Attach a bucket policy that denies uploads without the required KMS key.
AnswerA

Changing the S3 bucket's default encryption to SSE-KMS with a specified AWS KMS key ensures that all new objects uploaded to the bucket are automatically encrypted at rest using that customer-managed key. This eliminates the need for individual uploaders to specify encryption headers, significantly reducing the risk of unencrypted data and simplifying compliance requirements for sensitive user data. It's the most robust and operationally efficient method to enforce encryption for all objects.

Why this answer

The current bucket has default encryption set to SSE-S3, which uses AWS-managed keys, not customer-managed KMS keys. Changing the default encryption to SSE-KMS with the desired customer-managed KMS key ensures that all new objects uploaded to the bucket are automatically encrypted at rest using that key, meeting the security team's requirement without additional per-object configuration.

Exam trap

The trap here is that candidates often confuse enforcing encryption via bucket policies (which only denies non-compliant uploads) with actually setting the encryption method via default encryption, which automatically applies the required encryption to all objects.

How to eliminate wrong answers

Option B is wrong because adding object-level encryption settings after upload does not enforce encryption at rest for all objects; it requires manual intervention and does not change the default encryption behavior for future uploads. Option C is wrong because enabling S3 Bucket Keys reduces the number of KMS API calls for SSE-KMS but does not change the encryption type from SSE-S3 to SSE-KMS; it is an optimization feature, not a method to enforce customer-managed KMS encryption. Option D is wrong because a bucket policy that denies uploads without the required KMS key can enforce encryption requirements but does not change the default encryption configuration; it would still allow objects encrypted with SSE-S3 if the policy is not correctly crafted, and it does not automatically encrypt objects—it only denies unencrypted uploads, which is not the same as ensuring all data is encrypted at rest with the specified KMS key.

347
MCQhard

A company is using Amazon API Gateway to expose a set of RESTful APIs. Each API call is processed by an AWS Lambda function. The company wants to enforce throttling limits to prevent abuse. Specifically, the company wants to allow 100 requests per second per API key. What is the SIMPLEST way to achieve this?

A.Use AWS WAF to block requests after 100 per second.
B.Set a reserved concurrency on the Lambda function to 100.
C.Configure a CloudWatch alarm to disable the API key after exceeding the limit.
D.Create a usage plan in API Gateway with a rate limit of 100 requests per second per API key.
AnswerD

API Gateway usage plans are specifically designed to control access to API stages and methods by defining throttling and quota limits for individual API keys. By associating an API key with a usage plan, you can enforce precise rate limits, such as 100 requests per second, and burst limits on a per-consumer basis. This provides real-time, fine-grained control over API consumption, ensuring fair usage and protecting backend resources.

Why this answer

API Gateway usage plans are specifically designed to enforce throttling limits per API key. By creating a usage plan with a rate limit of 100 requests per second and associating it with the desired API keys, you can directly control request rates at the API Gateway layer without additional services or custom logic. This is the simplest and most native approach for per-API-key throttling.

Exam trap

The trap here is that candidates may confuse reserved concurrency (which limits Lambda execution concurrency) with API-level rate limiting, or assume that a reactive solution like CloudWatch alarms can enforce proactive throttling, when in fact API Gateway usage plans provide the simplest and most direct mechanism for per-API-key rate control.

How to eliminate wrong answers

Option A is wrong because AWS WAF is a web application firewall that filters traffic based on rules (e.g., IP sets, SQL injection), but it does not natively support per-API-key rate limiting; implementing such a limit would require custom logic and is not the simplest solution. Option B is wrong because reserved concurrency on a Lambda function limits the number of concurrent executions, not the request rate per second per API key; it also applies globally to the function, not per API key, and does not prevent abuse at the API Gateway level. Option C is wrong because a CloudWatch alarm can only trigger actions (e.g., disable an API key) after the limit is exceeded, but it cannot enforce a hard throttle in real time; the alarm would react after the fact, allowing bursts beyond 100 requests per second before any action is taken.

348
MCQmedium

A company wants to build a RESTful API that handles file uploads. The API needs to support multipart/form-data content type. The developer is using Amazon API Gateway and AWS Lambda. Which approach should the developer use to handle file uploads efficiently?

A.Configure API Gateway to pass the entire request body to Lambda, and process the file within the Lambda function.
B.Create a Lambda function that accepts the file and uploads it to S3 using the AWS SDK.
C.Use API Gateway to generate a presigned S3 URL, and have the client upload directly to S3. The Lambda function can then process the file asynchronously.
D.Use an EC2 instance to host a custom web server that accepts file uploads and writes to S3.
AnswerC

This is the recommended serverless pattern for large file uploads. API Gateway can authenticate the request and then generate a temporary, time-limited presigned URL for S3. The client then uses this URL to upload the file directly to S3, bypassing API Gateway and Lambda payload limits entirely. S3 can then asynchronously trigger a Lambda function (e.g., via S3 event notifications) to process the uploaded file, ensuring scalability and efficiency.

Why this answer

It offloads the file upload to Amazon S3 directly via a presigned URL, which avoids the 10 MB payload limit and 29-second timeout of API Gateway and Lambda for large files. The client uploads the file to S3, and a separate Lambda function processes the file asynchronously, making the solution efficient and scalable for multipart/form-data uploads.

Exam trap

The trap here is that candidates assume Lambda can handle file uploads directly via API Gateway, overlooking the 10 MB payload limit and 29-second timeout, and fail to recognize the presigned URL pattern as the efficient serverless solution for large multipart/form-data uploads.

How to eliminate wrong answers

Option A is wrong because API Gateway has a 10 MB payload limit and a 29-second integration timeout, making it unsuitable for large file uploads; passing the entire request body to Lambda also forces the function to handle raw multipart parsing, which is inefficient and error-prone. Option B is wrong because it still requires the client to send the file through API Gateway and Lambda, hitting the same size and timeout constraints; the Lambda function would need to receive the entire file payload before uploading to S3, defeating the purpose of direct upload. Option D is wrong because it introduces unnecessary infrastructure management (EC2) and does not leverage serverless benefits; it also does not address the requirement to use API Gateway and Lambda, and a custom web server on EC2 adds operational overhead without improving efficiency.

349
MCQmedium

A developer is building a microservices application composed of multiple AWS Lambda functions and an Amazon API Gateway. The developer needs to trace requests as they travel through different services to identify performance bottlenecks. Which AWS service should the developer integrate?

A.AWS CloudTrail
B.Amazon CloudWatch Logs
C.AWS X-Ray
D.Amazon Inspector
AnswerC

AWS X-Ray is purpose-built for distributed tracing, providing an end-to-end view of requests as they travel through your microservices application. It collects data about requests, generates a service map visualizing application components and their interconnections, and allows developers to identify performance bottlenecks, errors, and latency issues within individual services or across the entire request path. X-Ray's ability to trace requests across multiple services makes it invaluable for debugging and optimizing complex distributed systems.

Why this answer

AWS X-Ray is the correct service because it provides end-to-end tracing of requests as they travel through distributed applications, including AWS Lambda functions and API Gateway. It generates a service map that shows the flow of requests, latency breakdowns, and identifies performance bottlenecks across microservices. X-Ray integrates directly with Lambda and API Gateway via the X-Ray SDK and tracing headers, enabling trace propagation without code changes.

Exam trap

The trap here is that candidates confuse CloudWatch Logs (which shows logs) with distributed tracing (which correlates requests across services), leading them to pick CloudWatch Logs instead of X-Ray for end-to-end performance analysis.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API calls for auditing and governance, not for tracing individual request paths or performance bottlenecks across microservices. Option B is wrong because Amazon CloudWatch Logs aggregates log data but does not provide distributed tracing or service maps to correlate requests across multiple Lambda functions and API Gateway. Option D is wrong because Amazon Inspector is a vulnerability management service that scans for software vulnerabilities and network exposure, not for tracing application requests or performance analysis.

350
MCQmedium

A company uses Amazon API Gateway to expose a REST API. The API uses a Lambda authorizer to validate JWT tokens. Recently, the API has been returning 401 Unauthorized errors for valid tokens. The developer notices that the tokens are signed with a new key but the authorizer still uses the old key. What is the MOST efficient way to update the authorizer with the new key?

A.Modify the Lambda authorizer to fetch the public key from a well-known URL at runtime.
B.Update the API Gateway stage deployment to redeploy the API.
C.Delete and recreate the API Gateway authorizer with the new key.
D.Update the Lambda authorizer's environment variable with the new key and publish a new version.
AnswerA

Modifying the Lambda authorizer to fetch the public key from a well-known URL at runtime is the most robust solution. This approach leverages standard identity provider practices where public keys (often in JWKS format) are exposed at a predictable endpoint (e.g., `/.well-known/jwks.json`). The Lambda function can programmatically retrieve and cache these keys, ensuring it always uses the latest valid key for JWT signature verification without requiring any redeployment of the Lambda function or API Gateway when the key rotates. This significantly reduces operational overhead and enhances security by enabling seamless key rotation.

Why this answer

Fetching the public key from a well-known URL (e.g., the JWKS endpoint) at runtime allows the Lambda authorizer to automatically use the latest signing key without manual intervention. This approach decouples key rotation from the authorizer code, ensuring that valid tokens signed with the new key are accepted immediately. It is the most efficient method as it avoids redeployments, environment variable updates, or recreating the authorizer.

Exam trap

The trap here is that candidates assume updating environment variables or redeploying the API is sufficient, but they overlook that the authorizer must dynamically resolve the signing key to handle automatic key rotation without manual steps.

How to eliminate wrong answers

Option B is wrong because redeploying the API Gateway stage does not update the signing key used by the Lambda authorizer; it only deploys the current API configuration. Option C is wrong because deleting and recreating the authorizer is unnecessary and inefficient; the authorizer can be updated programmatically or by modifying its logic. Option D is wrong because updating an environment variable and publishing a new Lambda version still requires manual key rotation and does not address the root cause of dynamic key changes; the authorizer would still need to be updated each time the key changes.

351
Multi-Selectmedium

A company is using AWS Elastic Beanstalk to deploy a web application. The application uses an Amazon RDS MySQL database. The development team wants to ensure that database credentials are not exposed in the application code. Which THREE actions should the team take to securely manage and retrieve database credentials? (Choose three.)

Select 3 answers
A.Store the credentials in an S3 bucket with a bucket policy that restricts access to the application.
B.Configure Elastic Beanstalk to pass the secret ARN to the application as an environment property.
C.Modify the application code to retrieve the credentials from Secrets Manager at startup.
D.Hardcode the credentials in the application code and use environment variables to override them.
E.Store the database credentials in AWS Secrets Manager.
AnswersB, C, E

Passing the secret ARN as an environment property in Elastic Beanstalk is a secure pattern because the actual credential value is never embedded in code or environment configuration. The application retrieves the secret from AWS Secrets Manager at runtime using the ARN, while the Elastic Beanstalk instance profile supplies the necessary IAM permissions. This keeps the secret itself hidden and ensures the application always uses the current value, even if the secret is rotated.

Why this answer

Option E is correct because AWS Secrets Manager is the purpose-built service for storing and rotating sensitive data such as RDS MySQL credentials, keeping them out of source code and enabling fine-grained IAM access control. Option B is correct because passing the secret ARN (not the secret value) as an Elastic Beanstalk environment property lets the application know which secret to fetch without embedding credentials in code or configuration files. Option C is correct because the application must call the Secrets Manager API (e.g., GetSecretValue) at startup to retrieve the credentials dynamically, which completes the secure retrieval workflow.

Option A is not appropriate because S3 is object storage, not a secrets management service, and a bucket policy alone does not provide the encryption, rotation, and audit controls of Secrets Manager. Option D is wrong because hardcoding credentials in application code is exactly the insecure practice the team is trying to eliminate, and environment variable overrides do not remove the exposed secrets from the codebase.

Exam trap

DVA-C02 often tests whether candidates know that S3 is not a secrets store and that hardcoding credentials — even with environment variable overrides — still violates secure coding practices.

352
MCQmedium

A company runs a Node.js application on AWS Elastic Beanstalk. The application experiences high latency during peak hours. The developer suspects that the environment's EC2 instances are under-provisioned. Which configuration change would MOST effectively address the latency issue with minimal cost increase?

A.Place the environment behind an Application Load Balancer.
B.Enable Auto Scaling and configure scaling triggers based on CPU utilization.
C.Change the instance type to a larger size in the environment configuration.
D.Decrease the minimum number of instances in the Auto Scaling group.
AnswerB

Enabling Auto Scaling and configuring scaling triggers based on CPU utilization is the most effective and elastic solution for handling variable loads in a Node.js application. When the average CPU utilization across the Auto Scaling group exceeds a predefined threshold, new EC2 instances are automatically launched to distribute the workload, improving responsiveness and preventing performance degradation. Conversely, instances are terminated during periods of low utilization, optimizing operational costs.

Why this answer

Enabling Auto Scaling with CPU utilization triggers dynamically adds EC2 instances during peak hours, distributing the load and reducing latency without over-provisioning during off-peak times. This matches the symptom of under-provisioned instances and minimizes cost by scaling only when needed, unlike static solutions that waste resources.

Exam trap

The trap here is that candidates often confuse adding a load balancer (Option A) with solving capacity issues, but a load balancer only distributes traffic and does not increase compute resources, so latency remains if instances are saturated.

How to eliminate wrong answers

Option A is wrong because placing the environment behind an Application Load Balancer (ALB) alone does not address under-provisioned instances; an ALB distributes traffic but does not add compute capacity, so latency persists if instances are overloaded. Option C is wrong because changing to a larger instance type increases cost for all hours, including low-traffic periods, and does not dynamically adapt to peak demand, making it less cost-effective than Auto Scaling. Option D is wrong because decreasing the minimum number of instances reduces the baseline capacity, worsening latency during both peak and normal loads, as fewer instances handle the same traffic.

353
MCQmedium

A developer is using Amazon API Gateway to expose a REST API. The API needs to validate request parameters and payload before invoking the backend Lambda function. What is the MOST efficient way to perform this validation?

A.Use API Gateway request validation with a model schema.
B.Validate the request in the Lambda function and return errors if validation fails.
C.Use Amazon CloudFront to validate the request at the edge.
D.Use API Gateway request parameters to enforce required headers.
AnswerA

API Gateway's request validation leverages JSON Schema Draft 4 models to define the expected structure and data types for request bodies, headers, and query parameters. By configuring a validator for a method, API Gateway automatically inspects incoming requests against the defined schema. This pre-processing rejects malformed requests before they reach the backend, significantly reducing unnecessary Lambda invocations, saving costs, and improving API responsiveness.

Why this answer

API Gateway's built-in request validation allows you to define a JSON Schema model that automatically validates request parameters, headers, and payload before the request reaches the backend Lambda function. This offloads validation from the Lambda function, reducing compute time and cost, and provides immediate 400 error responses without invoking the backend. It is the most efficient approach because it minimizes latency and Lambda invocations for invalid requests.

Exam trap

The trap here is that candidates often assume validation must happen in the Lambda function (Option B) because they think backend logic is required, but API Gateway's built-in request validation is more efficient and is the recommended approach for schema-based validation before invocation.

How to eliminate wrong answers

Option B is wrong because validating in the Lambda function incurs unnecessary compute cost and latency, as the function must be invoked even for invalid requests, and it does not leverage API Gateway's native validation capabilities. Option C is wrong because Amazon CloudFront is a content delivery network (CDN) that caches and distributes content at the edge; it does not perform request validation against a schema or model, and its primary purpose is not to validate API requests. Option D is wrong because using API Gateway request parameters to enforce required headers only validates the presence of headers, not the payload body or complex parameter constraints, and it lacks the schema-based validation needed for payload structure.

354
MCQeasy

A developer is building a serverless application using AWS Lambda. The application needs to process messages from an Amazon SQS queue and store results in an Amazon DynamoDB table. Which AWS service should the developer use to trigger the Lambda function when new messages arrive in the SQS queue?

A.Set up an Amazon EventBridge rule to capture SQS events and invoke Lambda.
B.Use Amazon SNS to subscribe to the SQS queue and trigger Lambda.
C.Use AWS Step Functions to poll the SQS queue and invoke Lambda.
D.Configure an SQS event source mapping on the Lambda function.
AnswerD

Configuring an SQS event source mapping on a Lambda function is the correct and most efficient approach. This mechanism enables Lambda to automatically poll the specified SQS queue, retrieve batches of messages, and then synchronously invoke the Lambda function with these messages as the event payload. Lambda manages the polling infrastructure, scaling, and ensures messages are processed, deleted upon successful execution, or returned to the queue if the function fails.

Why this answer

AWS Lambda supports native SQS event source mappings, which allow Lambda to poll an SQS queue and invoke the function automatically when new messages arrive. This integration handles the polling, batch retrieval, and deletion of messages from the queue, making it the simplest and most efficient way to process SQS messages with Lambda.

Exam trap

The trap here is that candidates may confuse the direction of SNS-SQS integration, thinking SNS can subscribe to SQS to trigger Lambda, when in fact SNS publishes to SQS and Lambda must be triggered via an event source mapping or SNS topic subscription directly.

How to eliminate wrong answers

Option A is wrong because Amazon EventBridge rules cannot directly capture SQS events; SQS does not emit events to EventBridge for queue messages. Option B is wrong because Amazon SNS cannot subscribe to an SQS queue; SNS publishes messages to SQS subscriptions, not the reverse, and SNS cannot trigger Lambda from SQS messages. Option C is wrong because AWS Step Functions can poll SQS using a service integration, but it is not designed to trigger Lambda directly from new messages; it would require a custom polling loop or callback pattern, adding unnecessary complexity compared to the native SQS event source mapping.

355
Multi-Selecthard

A company is using AWS CodePipeline to automate its CI/CD pipeline. The pipeline has a source stage that pulls code from an Amazon S3 bucket. Which THREE steps should the developer take to ensure that only approved changes are deployed to production?

Select 3 answers
A.Use AWS CloudFormation change sets to review changes
B.Enable versioning on the S3 bucket
C.Configure cross-account access for the pipeline
D.Add a manual approval step before the production deployment
E.Encrypt the S3 bucket with AWS KMS
AnswersA, B, D

CloudFormation change sets provide a summary of proposed changes to your AWS resources before they are actually implemented. Integrating change sets into a CodePipeline stage allows developers to review the exact modifications (e.g., resource additions, deletions, or property updates) that a new CloudFormation template would make to the existing stack. This critical review step helps prevent unintended resource modifications or accidental deletions in production environments, ensuring controlled and predictable infrastructure updates.

Why this answer

AWS CloudFormation change sets allow you to preview how proposed changes to a stack will impact existing resources before you execute them. By reviewing the change set, you can verify that only approved modifications (e.g., infrastructure updates) are applied, providing a safety check before deployment to production. This step ensures that unapproved or unintended changes are caught early in the pipeline.

Exam trap

The trap here is that candidates often confuse security controls (like encryption or cross-account access) with governance controls (like approval workflows), leading them to select options that protect data but do not enforce change approval.

356
Multi-Selectmedium

A developer is designing a microservices architecture using Amazon ECS with Fargate. The services need to communicate with each other securely. Which THREE methods can be used to enable service-to-service authentication?

Select 3 answers
A.Use AWS App Mesh with mutual TLS (mTLS) authentication.
B.Configure Amazon ECS Service Connect for service-to-service communication.
C.Use Amazon API Gateway as a proxy for inter-service communication.
D.Use security group rules to allow traffic only between services.
E.Use IAM roles for tasks and AWS SDK to sign requests.
AnswersA, B, E

AWS App Mesh is a service mesh that provides application-level networking for microservices, leveraging Envoy proxies to manage all network traffic. It enables mutual TLS (mTLS) for strong identity-based authentication and encryption between services. This ensures that only trusted services can communicate, enhancing both security and observability within the microservices architecture by verifying the identity of both the client and server.

Why this answer

AWS App Mesh with mutual TLS (mTLS) provides service-to-service authentication by requiring each side of a connection to present and validate X.509 certificates. This ensures both the caller and the receiver are authenticated, preventing unauthorized services from communicating within the mesh.

Exam trap

The trap here is that candidates confuse network-layer controls (security groups) with application-layer authentication (mTLS, IAM), assuming that restricting traffic by IP/port is sufficient for service identity verification.

357
MCQhard

A developer is building a REST API using Amazon API Gateway and AWS Lambda. The API must support CORS to allow requests from a web application hosted on a different domain. The developer has enabled CORS on the API Gateway resource and configured the Lambda function to return the appropriate headers. However, the web application is still receiving CORS errors. What is the most likely cause?

A.The API Gateway stage is not redeployed after enabling CORS.
B.The API Gateway CORS configuration is incorrect; the allowed origin should be set to '*'.
C.The web application is not sending the preflight OPTIONS request.
D.The Lambda function is not returning the CORS headers in the response.
AnswerA

While redeploying an API Gateway stage is often necessary for configuration changes to take effect, a CORS error specifically indicates that the required `Access-Control-Allow-Origin` header is missing from the HTTP response. Even if the API Gateway's own CORS configuration is correctly set and deployed, if the integrated backend Lambda function does not explicitly include these headers in its response, the browser will still block the request. Therefore, redeployment alone would not resolve the fundamental issue of missing headers from the Lambda's output.

Why this answer

When you enable CORS in the API Gateway console, it creates or updates the OPTIONS method for the resource. However, these configuration changes do not take effect until the API is redeployed to a stage. If the developer does not redeploy the API, the preflight OPTIONS request will fail (typically returning a 403 or 404), which the browser interprets as a CORS error.

Since the developer already configured the Lambda function to return the headers, the missing step is redeploying the API stage.

Exam trap

Candidates often forget that enabling CORS in the API Gateway console modifies the API definition (by adding/updating the OPTIONS method and mock integration). Like any other method or resource change in API Gateway, these changes are not active on the live stage until the API is explicitly redeployed.

How to eliminate wrong answers

Option A is wrong because redeploying the API Gateway stage is necessary after any configuration change, but the question states the developer enabled CORS on the resource, implying the stage was redeployed; the core issue is the Lambda response missing headers. Option B is wrong because setting the allowed origin to '*' is a valid wildcard for CORS, but it does not fix the missing headers from the Lambda function; the problem is not the origin value but the absence of headers entirely. Option C is wrong because the browser automatically sends the preflight OPTIONS request for cross-origin requests with non-simple methods or custom headers; the developer enabled CORS on API Gateway, which handles the OPTIONS response, so the preflight is not the issue.

358
MCQeasy

A developer is deploying a new version of an AWS Lambda function that is invoked by an Amazon API Gateway REST API. The developer wants to shift 10% of incoming traffic to the new version while keeping 90% on the current version, and then gradually increase traffic to the new version. The developer also needs the ability to roll back instantly if errors occur. Which approach should the developer use?

A.Use AWS CodeDeploy to perform a blue/green deployment of the Lambda function, specifying a 10% traffic shift in the deployment configuration.
B.Publish a new Lambda function version and create an alias that points to both versions with a weighted routing configuration, then update the API Gateway integration to use the alias ARN.
C.Configure the API Gateway method to use a Lambda proxy integration and enable throttling to limit the new version's invocations.
D.Create a new API Gateway stage for the new Lambda version and use canary deployment settings on the stage to route 10% of traffic.
AnswerB

Lambda aliases support weighted routing between two versions, allowing traffic to be split by percentage. API Gateway can invoke the alias ARN, so the traffic distribution is managed at the alias level. This enables gradual shifts and instant rollback by adjusting weights or repointing the alias to the previous version.

Why this answer

Lambda aliases with weighted routing allow a developer to direct a percentage of invocations to a new version while keeping the rest on the current version. By pointing API Gateway to the alias ARN, the traffic split is enforced at the alias level. Adjusting the weights or repointing the alias provides immediate rollback, satisfying all requirements with minimal operational overhead.

Exam trap

The trap here is assuming that API Gateway stage canary settings or CodeDeploy are required for traffic shifting, when Lambda alias weighted routing directly provides the needed split and rollback.

359
MCQhard

A developer is building a serverless application using AWS Lambda and Amazon API Gateway REST API. The API Gateway is configured to use a Lambda proxy integration. The developer wants to return a custom error message with a specific HTTP status code (e.g., 404) when a resource is not found. How should the developer implement this?

A.Return a JSON object with 'status_code' and 'message' keys.
B.Throw an exception with a message that includes the HTTP status code.
C.Return a JSON object with 'errorMessage' and 'errorType' keys.
D.Return a JSON object with keys 'statusCode', 'headers', and 'body' where 'statusCode' is 404 and 'body' contains the error message.
AnswerD

For API Gateway Lambda proxy integration, the Lambda function must return a JSON object with the exact structure `{ 'statusCode': <number>, 'headers': <object>, 'body': <string> }`. This specific format allows the Lambda function to fully control the HTTP response returned to the client, including the status code (e.g., 404 Not Found), custom headers, and the response body containing the error message. Adhering to this contract ensures API Gateway correctly maps the Lambda's output to the desired HTTP response.

Why this answer

With Lambda proxy integration in API Gateway, the Lambda function must return a response in the exact format that API Gateway expects: a JSON object with 'statusCode' (integer), 'headers' (object), and 'body' (string). This allows the developer to set a custom HTTP status code like 404 and include a custom error message in the body. API Gateway will then map this response directly to the HTTP response sent to the client.

Exam trap

The trap here is that candidates often confuse the Lambda proxy integration response format with the standard Lambda error response format (errorMessage/errorType) or assume that simply throwing an exception will propagate the status code, but AWS requires a specific structured success response to control the HTTP status code.

How to eliminate wrong answers

Option A is wrong because returning a JSON object with 'status_code' and 'message' keys does not match the required response format for Lambda proxy integration; API Gateway will not interpret these keys and will likely return a 502 Malformed Lambda Response. Option B is wrong because throwing an exception in Lambda causes the function to fail, and API Gateway will return a 502 Internal Server Error, not the custom status code or message. Option C is wrong because 'errorMessage' and 'errorType' are part of the standard error response format for Lambda invocations (used in non-proxy integrations or direct invocations), but with proxy integration, the Lambda must return a properly formatted success response, not an error object.

360
MCQhard

A company runs a stateful web application on EC2 instances behind an Application Load Balancer. The application uses WebSockets for real-time communication. The company wants to use AWS CodeDeploy to deploy updates with minimal downtime. Which deployment configuration should the developer use?

A.Canary deployment.
B.In-place deployment.
C.Blue/green deployment.
D.Immutable deployment.
AnswerC

Blue/green deployment involves creating an entirely new, identical environment (the "green" environment) running the new version of the application alongside the existing "blue" environment. Traffic remains directed to the stable "blue" environment while the "green" environment is thoroughly tested. Once verified, traffic is seamlessly shifted from "blue" to "green" at the load balancer level. This approach ensures zero downtime and preserves existing user sessions on the "blue" environment until the switch is complete, making it ideal for stateful applications.

Why this answer

Blue/green deployment is correct because it allows the company to deploy a new version of the application on a separate set of EC2 instances (green environment) while the current version continues to serve traffic on the original set (blue environment). Once the green environment is fully tested and healthy, the Application Load Balancer can instantly switch traffic to it, minimizing downtime. This approach is ideal for stateful WebSocket applications because it avoids terminating active connections during the deployment, as the blue environment remains operational until the switch is complete.

Exam trap

The trap here is that candidates often confuse 'immutable deployment' with a valid CodeDeploy option, but AWS CodeDeploy only supports blue/green and in-place deployments, while immutable deployments are a concept from Elastic Beanstalk or EC2 Auto Scaling with launch template versioning.

How to eliminate wrong answers

Option A is wrong because a canary deployment gradually shifts a small percentage of traffic to the new version, which can cause issues with stateful WebSocket connections that require session persistence and may not handle partial traffic shifts gracefully. Option B is wrong because an in-place deployment updates the existing EC2 instances one at a time, which terminates active WebSocket connections and disrupts real-time communication, leading to downtime. Option D is wrong because immutable deployment is not a standard AWS CodeDeploy deployment configuration; AWS CodeDeploy supports blue/green and in-place deployments, but immutable deployments are typically associated with AWS Elastic Beanstalk or EC2 Auto Scaling with launch templates, not CodeDeploy.

361
MCQeasy

A company uses AWS Elastic Beanstalk to deploy a web application. The application stores user-uploaded images in an S3 bucket. The developer needs to ensure that the application can read and write to the S3 bucket. What should the developer do?

A.Use Amazon CloudFront to proxy requests to the S3 bucket.
B.Hardcode the AWS access keys in the application code.
C.Apply an S3 bucket policy that allows access from the Elastic Beanstalk environment's security group.
D.Configure the Elastic Beanstalk environment to use an IAM instance profile that grants S3 access.
AnswerD

Configuring the Elastic Beanstalk environment to use an IAM instance profile that grants S3 access is the recommended and most secure method. An IAM instance profile attaches an IAM role to the underlying EC2 instances, allowing the application to obtain temporary, automatically rotated credentials from the instance metadata service. This enables the application to make authenticated AWS API calls to S3 without storing any long-term credentials directly within the application code or configuration.

Why this answer

Elastic Beanstalk environments run on EC2 instances, and the recommended way to grant AWS permissions to those instances is by attaching an IAM instance profile. This profile includes an IAM role with a policy that allows the required S3 read and write actions, enabling the application to securely access the S3 bucket without embedding credentials in the code.

Exam trap

The trap here is that candidates may confuse network-level controls (security groups) with identity-based controls (IAM roles) and incorrectly assume that an S3 bucket policy can reference a security group, when in fact S3 bucket policies support only principal, source IP, VPC, or source VPC endpoint conditions, not security group IDs.

How to eliminate wrong answers

Option A is wrong because Amazon CloudFront is a content delivery network (CDN) that can cache and serve content from S3, but it does not grant the application itself the ability to read/write to the bucket; it only proxies requests from clients. Option B is wrong because hardcoding AWS access keys in application code violates security best practices, as keys can be exposed in version control or logs, and Elastic Beanstalk provides a more secure mechanism via instance profiles. Option C is wrong because S3 bucket policies can restrict access by source IP or VPC, but they cannot reference EC2 security groups directly; security groups are a network-level construct, not an identity-based one, and S3 does not evaluate security group IDs in bucket policies.

362
MCQmedium

A company is developing a microservices architecture using Amazon ECS with Fargate launch type. Each microservice needs to store sensitive configuration data such as database passwords. The company wants to avoid storing secrets in the application code or environment variables. What is the MOST secure and recommended approach?

A.Pass secrets as environment variables in the task definition.
B.Store secrets in an encrypted S3 bucket and have the application download them at startup.
C.Use AWS Systems Manager Parameter Store or AWS Secrets Manager to store and retrieve secrets.
D.Use an AWS Lambda function to generate secrets and store them in DynamoDB.
AnswerC

AWS Systems Manager Parameter Store (specifically Secure String parameters) and AWS Secrets Manager are purpose-built services designed for the secure storage, retrieval, and rotation of sensitive information. They integrate natively with AWS Key Management Service (KMS) for encryption at rest and AWS Identity and Access Management (IAM) for fine-grained access control, providing a robust and compliant solution for managing secrets in a microservices architecture.

Why this answer

AWS Systems Manager Parameter Store (SecureString) and AWS Secrets Manager are purpose-built services for storing and retrieving secrets securely, with encryption at rest via KMS, fine-grained IAM access control, and native integration with ECS/Fargate task definitions. Secrets Manager additionally supports automatic rotation. This is the AWS-recommended approach for injecting secrets into containerized workloads without hardcoding them.

Exam trap

DVA-C02 often tests the misconception that environment variables in task definitions are secure — candidates pick option A because it is convenient, missing that task definition environment variables are visible in plaintext via the ECS API and console.

How to eliminate wrong answers

Option A is wrong because environment variables in task definitions are visible in the ECS console, API responses, and container metadata — they are not a secure storage mechanism for sensitive data. Option B is wrong because downloading secrets from S3 at startup requires the application to manage decryption, caching, and rotation itself, and S3 is not designed as a secrets store — it lacks rotation and fine-grained secret-level access controls. Option D is wrong because using Lambda to generate secrets and store them in DynamoDB creates a custom, unmanaged secrets pipeline with no rotation, no encryption-by-default guarantees, and unnecessary operational complexity.

363
Multi-Selectmedium

A developer is implementing S3 multipart upload for large files. Which two actions are required to complete the upload?

Select 2 answers
A.Enable S3 static website hosting
B.Upload all parts and keep their ETags/part numbers
C.Disable bucket encryption
D.Call CompleteMultipartUpload with the uploaded part list
AnswersB, D

After initiating a multipart upload, the core process involves uploading each individual part of the large file using the `UploadPart` API operation. For every successful part upload, Amazon S3 returns a unique ETag (entity tag) and the corresponding part number. It is critical to store these ETags and part numbers, as they are mandatory parameters for the subsequent `CompleteMultipartUpload` request, which reassembles the parts into the final object.

Why this answer

During an S3 multipart upload, each part must be uploaded individually, and the response includes an ETag (a hash of the part) and a part number. These must be recorded and provided in the final request to assemble the object. Option D is correct because the CompleteMultipartUpload API call is required to signal S3 to combine all uploaded parts into the final object, using the list of ETags and part numbers.

Exam trap

The trap here is that candidates may think uploading all parts is sufficient without calling CompleteMultipartUpload, or they may confuse the multipart upload process with other S3 features like static hosting or encryption settings.

364
MCQeasy

A developer is building an application that needs to send email notifications to users. Which AWS service is designed for sending transactional emails?

A.AWS Lambda
B.Amazon Simple Email Service (SES)
C.Amazon Simple Notification Service (SNS)
D.Amazon Simple Queue Service (SQS)
AnswerB

Amazon Simple Email Service (SES) is a highly scalable, cost-effective, and flexible cloud-based email sending service designed for developers to send marketing, notification, and transactional emails from any application. It handles the underlying email infrastructure, including SMTP, deliverability, and reputation management, allowing applications to programmatically send emails via API, SDKs, or SMTP interface. This makes SES the ideal choice for applications requiring direct email sending capabilities.

Why this answer

Amazon Simple Email Service (SES) is specifically designed for sending transactional emails, such as order confirmations, password resets, and marketing communications. It provides a reliable, scalable SMTP interface or API to send high-deliverability emails, with features like dedicated IP addresses and feedback loops. This makes it the correct choice for an application that needs to send email notifications directly to users.

Exam trap

The trap here is that candidates often confuse Amazon SNS with SES because both can send notifications, but SNS is limited to push notifications (SMS, mobile push, HTTP) and cannot send rich transactional emails, while SES is the dedicated email service.

How to eliminate wrong answers

Option A is wrong because AWS Lambda is a serverless compute service for running code in response to events, not a service for sending emails; it could be used to trigger email sending via SES, but it is not the email delivery service itself. Option C is wrong because Amazon Simple Notification Service (SNS) is a pub/sub messaging service designed for sending push notifications to endpoints like SMS, mobile apps, or HTTP/HTTPS, not for sending transactional emails with rich content or attachments. Option D is wrong because Amazon Simple Queue Service (SQS) is a fully managed message queuing service for decoupling application components, and it has no capability to send emails; it can only hold messages for processing by other services.

365
MCQhard

A company runs a microservices architecture on Amazon ECS with Fargate. Each service uses an Application Load Balancer and stores data in Amazon DynamoDB. The operations team notices that during traffic spikes, some requests fail with HTTP 503 errors. CloudWatch metrics show that the ALB's TargetResponseTime is increasing, and the DynamoDB table's ConsumedWriteCapacityUnits are reaching the provisioned limit. The team wants to handle traffic spikes gracefully without manual intervention. What should they do?

A.Increase the DynamoDB table's provisioned write capacity and the ALB's target group deregistration delay.
B.Use an SQS queue to buffer write requests and process them asynchronously.
C.Add a DynamoDB Accelerator (DAX) cluster to cache frequently accessed data.
D.Enable DynamoDB Auto Scaling for write capacity and configure ECS Service Auto Scaling based on ALB request count.
AnswerD

Enabling DynamoDB Auto Scaling for write capacity allows the table to automatically adjust its provisioned throughput based on actual utilization and defined target metrics, preventing throttling during peak loads and scaling down during lulls to optimize costs. Concurrently, configuring ECS Service Auto Scaling based on the ALB request count ensures that the microservices processing the requests will dynamically add or remove tasks to match incoming traffic, providing sufficient compute resources to handle the increased demand and effectively utilize the scaled DynamoDB capacity. This combination offers a fully automated, elastic, and cost-efficient solution.

Why this answer

DynamoDB Auto Scaling automatically adjusts the provisioned write capacity based on traffic, preventing throttling and 503 errors from write capacity exhaustion. ECS Service Auto Scaling adds more tasks when the ALB request count increases, distributing the load. Together, they handle traffic spikes without manual intervention.

Option A is wrong because manually increasing provisioned capacity does not scale automatically, and deregistration delay does not address capacity issues. Option B is wrong because while SQS can buffer write requests, it adds complexity and latency; the question asks for graceful handling, and auto scaling addresses the root cause more directly. Option C is wrong because DAX is a cache for read operations, not write capacity.

366
Multi-Selecthard

A company is using AWS CodePipeline to automate its deployment pipeline. The pipeline has a source stage that pulls code from Amazon S3, a build stage using AWS CodeBuild, and a deploy stage using AWS CodeDeploy. The developer wants to add a manual approval step before deployment to production. Which of the following are correct steps to implement this? (Choose THREE.)

Select 3 answers
A.Add a second pipeline for the approval step.
B.Configure the approval action to use an SNS topic for notifications.
C.Use AWS CodeBuild to run a script that waits for manual approval.
D.Create an IAM role that allows the pipeline to publish to the SNS topic.
E.Add an approval action to the pipeline before the deploy stage.
AnswersB, D, E

When a manual approval action is configured in AWS CodePipeline, it can be integrated with Amazon SNS to send notifications to designated approvers. Upon reaching the approval stage, CodePipeline publishes a message to the specified SNS topic, which can then trigger email subscriptions or other endpoints to alert approvers. This ensures timely communication and allows approvers to access the approval console link directly from the notification, facilitating a prompt decision.

Why this answer

AWS CodePipeline approval actions can be configured to send notifications via Amazon SNS when the action requires manual approval. This allows approvers to be alerted that an approval is pending, enabling timely review and progression of the pipeline.

Exam trap

The trap here is that candidates may think a separate pipeline or a custom script is needed for manual approval, but AWS CodePipeline provides a built-in approval action that integrates directly with SNS and IAM, making those external workarounds incorrect.

367
MCQmedium

A developer is deploying an application on Amazon ECS using the Fargate launch type. The application needs to communicate with a DynamoDB table. The developer creates a VPC with private subnets and configures the ECS service to use those subnets. However, the tasks cannot reach DynamoDB. What is the MOST likely cause?

A.The task IAM role does not have permissions to access DynamoDB.
B.The security group of the tasks does not allow outbound traffic to DynamoDB.
C.The VPC does not have a VPC endpoint for DynamoDB, and there is no NAT gateway.
D.The task definition does not have a network mode that supports DynamoDB.
AnswerC

When an ECS task runs in a private subnet, it lacks a direct route to the internet, which is necessary to reach public AWS service endpoints like DynamoDB. Without a NAT Gateway to provide outbound internet access or a VPC endpoint for DynamoDB (a Gateway Endpoint for DynamoDB specifically), the task has no network path to communicate with the DynamoDB service. This configuration prevents any successful API calls from the private subnet.

Why this answer

ECS tasks using the Fargate launch type in private subnets cannot reach public AWS services like DynamoDB unless the VPC has either a NAT gateway (to route traffic through an internet gateway) or a VPC endpoint for DynamoDB. Without one of these, the private subnets have no route to the DynamoDB API endpoints, causing connectivity failures. The IAM role and security group are configured correctly, but the network path is missing.

Exam trap

The trap here is that candidates often assume IAM permissions (Option A) are the sole cause of access failures, overlooking the network-layer requirement that private subnets need a route to public AWS services via a NAT gateway or VPC endpoint.

How to eliminate wrong answers

Option A is wrong because the task IAM role controls permissions to DynamoDB actions (e.g., GetItem, PutItem), but if the tasks cannot reach the DynamoDB endpoint at the network level, permissions are irrelevant—the request never arrives. Option B is wrong because security groups are stateful; outbound traffic is allowed by default unless explicitly denied, and DynamoDB does not require a specific outbound rule for HTTPS (port 443) since the default outbound rule allows all traffic. Option D is wrong because the network mode (e.g., awsvpc, bridge, host) does not affect the ability to reach DynamoDB; Fargate requires the awsvpc mode, which assigns an elastic network interface to each task, but this does not block outbound traffic to DynamoDB.

368
MCQeasy

A developer has written an AWS Lambda function that processes messages from an Amazon SQS queue. The function is configured with a reserved concurrency of 5. The SQS queue has 10,000 messages waiting to be processed. What will happen when the Lambda function is invoked?

A.Lambda will automatically increase reserved concurrency to handle the load.
B.Lambda will reject the invocation because reserved concurrency is too low.
C.Lambda will scale up to 20 concurrent executions to process all messages quickly.
D.Lambda will process messages with a maximum of 5 concurrent executions, each processing a batch of messages.
AnswerD

This statement accurately describes the behavior of a Lambda function configured with reserved concurrency. The function will scale up to, but not exceed, the specified limit of 5 concurrent executions. Each of these concurrent executions will then process a batch of messages from the event source, ensuring that the processing adheres strictly to the defined concurrency constraint.

Why this answer

AWS Lambda integrates with Amazon SQS to poll the queue and invoke the function with batches of messages. The reserved concurrency of 5 caps the maximum number of concurrent executions, so Lambda will process messages with up to 5 concurrent invocations, each receiving a batch of up to 10 messages (default batch size). The remaining messages remain in the queue until they are processed or the visibility timeout expires.

Exam trap

The trap here is that candidates assume Lambda will automatically scale to handle the queue depth, but reserved concurrency is a hard limit that prevents scaling beyond the configured value, leading to throttling rather than rejection or automatic scaling.

How to eliminate wrong answers

Option A is wrong because reserved concurrency is a hard limit that Lambda cannot automatically increase; it must be manually adjusted or removed. Option B is wrong because Lambda does not reject invocations due to low reserved concurrency; it simply throttles the function, and unprocessed messages remain in the SQS queue. Option C is wrong because Lambda cannot scale beyond the reserved concurrency of 5, regardless of the number of messages in the queue.

369
MCQmedium

A developer is building a REST API using Amazon API Gateway and wants to transform the request data before sending it to the backend Lambda function. The transformation includes mapping query string parameters to a JSON body. Which API Gateway feature should be used?

A.Velocity Template Language (VTL) mapping templates
B.Lambda authorizer
C.Request validator
D.CORS configuration
AnswerA

Velocity Template Language (VTL) mapping templates are a core feature within API Gateway's integration request and response stages. They enable the transformation of incoming client request payloads and outgoing backend responses into formats compatible with the integration. This includes converting query string parameters, path parameters, or headers into a structured JSON body, or vice-versa, making them essential for adapting data formats between client and backend services.

Why this answer

API Gateway uses Velocity Template Language (VTL) mapping templates to transform incoming request data, such as mapping query string parameters into a JSON body before passing it to the backend Lambda function. This feature allows you to define a template that extracts values from the request's query string parameters (e.g., `$input.params('paramName')`) and constructs a new JSON payload, enabling seamless integration with Lambda without modifying the client request.

Exam trap

The trap here is that candidates often confuse request validation (Option C) with data transformation, assuming that validating the request structure also implies the ability to reshape the data, but validation only checks for presence and format, not mapping or transformation.

How to eliminate wrong answers

Option B is wrong because a Lambda authorizer is used for custom authentication and authorization of API requests, not for transforming request data or mapping parameters to a JSON body. Option C is wrong because a request validator only validates that the request adheres to the API's defined schema (e.g., required parameters, types), but it does not perform any data transformation or mapping. Option D is wrong because CORS configuration manages cross-origin resource sharing headers (e.g., Access-Control-Allow-Origin) to allow browser-based clients from different domains, and it has no role in transforming request payloads or mapping query string parameters.

370
MCQhard

A company has a production application running on AWS Lambda that processes real-time streaming data from Amazon Kinesis Data Streams. The Lambda function is configured with a batch size of 100 and a maximum concurrency of 5. Recently, the application has been experiencing failures with a high number of invocation errors. The errors indicate that the function is timing out. The developer checks the CloudWatch metrics and notices that the IteratorAge metric for the Kinesis stream is increasing rapidly, and there are many Throttles events for the Lambda function. The average execution duration of the function is 30 seconds, and the function timeout is set to 1 minute. The Kinesis stream has 10 shards. The company expects the data volume to double in the next month. Which combination of actions should the developer take to resolve the issue and prepare for future growth?

A.Increase the number of shards in the Kinesis stream to 20 and increase Lambda concurrency to 10.
B.Increase Lambda concurrency to at least 20 and reduce the batch size to 10.
C.Disable the reserved concurrency limit on the Lambda function and decrease the batch size to 5.
D.Increase the Lambda function timeout to 5 minutes and increase the batch size to 500.
AnswerB

Increasing Lambda concurrency to at least 20 allows the function to process more batches in parallel, effectively utilizing the Kinesis stream's capacity and reducing event backlog. Simultaneously, reducing the batch size to 10 records per invocation decreases the processing time for each individual invocation, making the function more efficient and less prone to timeouts, thereby improving overall throughput and mitigating throttling.

Why this answer

The Lambda function is throttled because the maximum concurrency of 5 is too low for 10 shards. With a batch size of 100 and average duration of 30 seconds, each batch takes too long, leading to timeouts and increasing IteratorAge. Increasing concurrency to at least 20 (2 per shard) allows processing of all shards in parallel.

Reducing batch size to 10 reduces the processing time per batch, helping avoid timeouts. Option A is wrong because increasing shards without increasing concurrency would worsen throttling. Option C is wrong because disabling reserved concurrency could lead to uncontrolled scaling, but the main issue is concurrency and batch size; also decreasing batch size to 5 may be too small and inefficient.

Option D is wrong because increasing timeout and batch size would not resolve throttling and would increase latency.

371
MCQmedium

A developer invokes an AWS Lambda function and receives a timeout error. The function is configured with a 3-second timeout. The developer needs to process data that sometimes takes up to 10 seconds. What should the developer do?

A.Change the invocation type to Event (async).
B.Increase the Lambda function timeout to 10 seconds.
C.Increase the memory allocation for the Lambda function.
D.Set reserved concurrency to 1.
AnswerB

The Lambda function timeout setting directly controls the maximum amount of time a function is allowed to execute before the AWS Lambda service forcibly terminates it. If a function is consistently timing out, it indicates that its current execution duration exceeds the configured limit. Increasing this timeout value to 10 seconds directly addresses the problem by providing the function with sufficient time to complete its operations successfully, preventing premature termination.

Why this answer

The error indicates the Lambda function is timing out because its configured timeout of 3 seconds is insufficient for processing that sometimes takes up to 10 seconds. Option B directly addresses this by increasing the timeout to 10 seconds, which is within the maximum Lambda timeout of 15 minutes (900 seconds). This ensures the function can complete its execution without being prematurely terminated.

Exam trap

The trap here is that candidates may confuse increasing memory (which can improve performance but does not extend the timeout) with solving a timeout error, or incorrectly assume that changing the invocation type to async will allow the function to run longer.

How to eliminate wrong answers

Option A is wrong because changing the invocation type to Event (async) does not increase the execution time available to the function; it only changes how the function is triggered, and the function would still time out after 3 seconds. Option C is wrong because increasing memory allocation can improve CPU performance and potentially reduce execution time, but it does not guarantee that the function will finish within 3 seconds if the data processing inherently requires up to 10 seconds; the timeout must be increased. Option D is wrong because setting reserved concurrency to 1 limits the number of concurrent executions but does not affect the function's timeout duration, so the function would still fail with a timeout error.

372
Multi-Selecthard

A developer is building a real-time chat application using WebSocket APIs in API Gateway and Lambda. The application must handle thousands of concurrent connections. Which TWO actions should the developer take to ensure the application scales properly?

Select 2 answers
A.Use CloudFront to distribute the WebSocket endpoints.
B.Place the Lambda function in a VPC to improve security.
C.Enable API Gateway caching to reduce Lambda invocations.
D.Set the Lambda function's reserved concurrency to a high enough value.
E.Use a DynamoDB table to store connection IDs and handle connection state.
AnswersD, E

For a real-time chat application, sudden bursts of user activity can lead to a large volume of concurrent Lambda invocations. Setting a high enough reserved concurrency guarantees that a specified number of execution environments are always available exclusively for this specific Lambda function, preventing it from being throttled by the account's unreserved concurrency pool. This ensures the function can consistently process messages and maintain responsiveness even during peak load, which is critical for delivering a smooth and reliable real-time chat experience.

Why this answer

Setting reserved concurrency ensures the Lambda function has enough allocated capacity to handle the high volume of concurrent WebSocket connections without being throttled by the account-level concurrency limit. Without reserved concurrency, the function could experience throttling errors (HTTP 429) during traffic spikes, causing dropped connections and poor user experience.

Exam trap

A common pitfall is assuming CloudFront can help scale WebSocket APIs for concurrent connections. While CloudFront does support WebSocket connections, it does not address the backend Lambda scaling or state management required for thousands of connections. The correct scaling actions are setting reserved concurrency for the Lambda function and storing connection IDs in DynamoDB for state management.

Similarly, enabling API Gateway caching or placing Lambda in a VPC do not solve the concurrency scaling issue.

373
MCQeasy

A developer wants to deploy a containerized application to Amazon ECS using Fargate. The application requires persistent storage that can be shared across multiple containers in the same task. Which storage option should the developer use?

A.Amazon EC2 instance store
B.Amazon EFS file system
C.Amazon S3 bucket
D.Amazon EBS volume
AnswerB

Amazon EFS (Elastic File System) provides scalable, elastic, shared file storage that can be accessed concurrently by multiple AWS Fargate tasks. It offers persistent storage, ensuring data remains available even if containers are stopped, replaced, or scaled. This makes EFS an excellent choice for containerized applications requiring shared state, persistent data, or a common file system across different application instances running on Fargate.

Why this answer

Amazon EFS provides a shared, persistent, and scalable file system that can be mounted by multiple containers within the same ECS task using Fargate. EFS supports the Network File System (NFS) protocol, allowing concurrent read/write access from all containers in the task, which meets the requirement for shared persistent storage. Unlike ephemeral or block storage options, EFS is designed for multi-attach scenarios and persists independently of the container lifecycle.

Exam trap

The trap here is that candidates often confuse Amazon EBS with a shared storage solution, but EBS volumes cannot be attached to multiple Fargate containers or tasks simultaneously, making EFS the only correct choice for shared persistent storage in this context.

How to eliminate wrong answers

Option A is wrong because Amazon EC2 instance store provides ephemeral block storage that is tied to the lifecycle of an EC2 instance, not a Fargate task, and cannot be shared across multiple containers. Option C is wrong because Amazon S3 is an object storage service accessed via HTTP/HTTPS APIs, not a file system mountable via NFS, and does not provide the POSIX-compliant shared file system required for concurrent container access. Option D is wrong because Amazon EBS volumes are block-level storage that can only be attached to a single EC2 instance at a time (unless using multi-attach EBS, which is not supported with Fargate), and cannot be shared across multiple containers in the same Fargate task.

374
MCQmedium

A developer is using AWS Elastic Beanstalk to deploy a web application. The application needs to store session state. Which configuration is MOST cost-effective and scalable?

A.Use S3 to store session state
B.Use an ElastiCache Memcached cluster
C.Use an RDS database to store session state
D.Store session state in the local file system of each EC2 instance
AnswerB

An ElastiCache Memcached cluster provides a highly scalable, in-memory key-value store perfectly suited for transient session state. Its distributed nature allows multiple EC2 instances in an Elastic Beanstalk environment to access shared session data with very low latency. This ensures user sessions persist even if requests are routed to different instances by a load balancer, enhancing application scalability and user experience.

Why this answer

ElastiCache Memcached is the most cost-effective and scalable solution for storing session state because it is an in-memory cache designed for low-latency access, which is ideal for session data that must be frequently read and written. It scales horizontally by adding nodes, and its distributed nature ensures that session data persists across EC2 instance replacements, unlike local storage. This avoids the higher cost and overhead of RDS or the latency and eventual consistency issues of S3 for session management.

Exam trap

The trap here is that candidates often choose local file system storage (D) because it seems simplest and free, overlooking that it fails in auto-scaling environments where instances are ephemeral and session data is not shared.

How to eliminate wrong answers

Option A is wrong because S3 is an object store with higher latency and eventual consistency, making it unsuitable for session state that requires fast, consistent reads and writes; it also incurs per-request costs that can become expensive under high traffic. Option C is wrong because RDS is a relational database with higher cost and operational overhead (e.g., provisioning, scaling, backups) compared to an in-memory cache, and it is overkill for simple key-value session data. Option D is wrong because storing session state in the local file system of each EC2 instance breaks when instances are replaced or scaled out, as session data is not shared across instances, leading to data loss and poor scalability.

375
Multi-Selecthard

A company uses Amazon API Gateway to expose a REST API backed by AWS Lambda. The API has a resource /items with GET and POST methods. The GET method returns items from a DynamoDB table. The POST method adds an item to the table. Currently, all methods are open to the public. Security requirements mandate that only authenticated users can access the POST method, while the GET method remains public. Which THREE steps should the developer take to meet these requirements?

Select 3 answers
A.Configure the Lambda authorizer only on the POST method in the API Gateway.
B.Create a Lambda function as an authorizer that validates a JWT token from the Authorization header.
C.In the Lambda authorizer, return an IAM policy that allows execute-api:Invoke on the POST method.
D.Use an Amazon Cognito User Pools authorizer for the entire API.
E.Add a resource policy that denies public access to the POST method.
AnswersA, B, C

API Gateway allows authorizers to be configured at the method level, providing fine-grained access control. By attaching the Lambda authorizer specifically to the POST method, the company ensures that only requests targeting this particular method are subjected to the custom authorization logic, while other methods remain unaffected or use different authorization mechanisms. This meets the requirement to secure only the POST method.

Why this answer

You can configure a Lambda authorizer at the method level in API Gateway, which allows you to selectively secure only the POST method while leaving the GET method public. This meets the requirement of restricting access to authenticated users for POST only, without affecting the public GET endpoint.

Exam trap

The trap here is that candidates often assume a resource policy can be used to selectively restrict methods, but resource policies apply at the API or stage level, not at the individual method level, making them unsuitable for this granular requirement.

← PreviousPage 5 of 6 · 388 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Dev AWS Services questions.