Courseiva

CCNA Dev AWS Services Questions

13 of 388 questions · Page 6/6 · Dev AWS Services topic · Answers revealed

376
Multi-Selecthard

A Lambda function processes messages from an SQS standard queue and writes results to DynamoDB. Duplicate writes occasionally occur after retries. Which two changes best make the processing idempotent?

Select 2 answers
A.Use a deterministic idempotency key stored with a conditional write in DynamoDB
B.Increase the Lambda timeout to 15 minutes
C.Treat the SQS message ID or business transaction ID as a processed-record key
D.Disable SQS visibility timeout
AnswersA, C

SQS Standard queues provide at-least-once delivery, meaning messages can be delivered multiple times. Implementing idempotency is crucial to prevent duplicate processing side effects. By generating a deterministic key (e.g., from the SQS message ID or a business transaction ID) and storing it in DynamoDB with a conditional write (e.g., using `attribute_not_exists`), the Lambda function ensures that the operation only proceeds if the key hasn't been recorded before, making the operation safe for retries and preventing unintended state changes.

Why this answer

Using a deterministic idempotency key (e.g., a business transaction ID) combined with a conditional write in DynamoDB ensures that if the same message is processed more than once, the second write attempt will fail because the item already exists. This prevents duplicate records even when Lambda retries after a failure or timeout, making the processing idempotent at the database level.

Exam trap

The trap here is that candidates often confuse idempotency with simply increasing timeouts or disabling visibility timeouts, not realizing that idempotency requires a deterministic key and a conditional check at the storage layer.

377
MCQeasy

A developer wants to store session state for a web application that runs on multiple EC2 instances behind an Application Load Balancer. Which AWS service should the developer use to store the session state in a centralized, highly available location?

A.Amazon RDS
B.Amazon S3
C.Amazon ElastiCache
D.AWS Lambda
AnswerC

Amazon ElastiCache is a fully managed in-memory caching service, offering high-performance, low-latency data retrieval using Redis or Memcached engines. It is specifically designed for use cases like session state management, where rapid access to frequently changing, ephemeral key-value data is critical. Its in-memory nature significantly reduces I/O latency compared to disk-based solutions, ensuring a responsive user experience and easily scaling to handle high request volumes.

Why this answer

Amazon ElastiCache is the correct choice because it provides a managed, in-memory caching service that supports Redis or Memcached, which are ideal for storing session state in a centralized, highly available manner. Session data requires low-latency reads and writes, and ElastiCache offers sub-millisecond performance, replication across multiple Availability Zones, and automatic failover, making it suitable for stateless web applications behind an Application Load Balancer.

Exam trap

The trap here is that candidates mistakenly choose Amazon RDS for session storage due to its familiarity with databases, overlooking that session state is transient and requires low-latency access, which ElastiCache's in-memory architecture provides far more efficiently.

How to eliminate wrong answers

Option A is wrong because Amazon RDS is a relational database service designed for persistent, structured data with ACID compliance, not for transient session state; its higher latency and connection overhead make it suboptimal for frequent session reads/writes. Option B is wrong because Amazon S3 is an object storage service with eventual consistency for read-after-write in some cases, and its higher latency (typically tens of milliseconds) and lack of native session expiration mechanisms make it unsuitable for real-time session state management. Option D is wrong because AWS Lambda is a serverless compute service for running code in response to events, not a data store; it cannot natively persist session state across invocations without an external storage layer like ElastiCache or DynamoDB.

378
MCQhard

A developer is deploying an application using AWS CloudFormation. The template includes an AWS::Lambda::Function resource. The developer wants to ensure that the Lambda function's code is automatically updated when the source code in S3 changes. Which approach should the developer use?

A.Specify the S3 object version in the template and update the version number in the template when code changes.
B.Use the AWS::Lambda::Version resource to create a new version.
C.Include the S3 bucket and key as template parameters and update the stack with a new key when code changes.
D.Use a custom resource backed by a Lambda function that polls S3 for changes.
AnswerA

When a Lambda function's code is sourced from S3, CloudFormation monitors the S3ObjectVersion property within the Code block of the AWS::Lambda::Function resource. By explicitly including the S3 object's version ID in the template and updating this ID upon each code change, CloudFormation detects a modification to the resource's properties. This change then triggers an update to the Lambda function, ensuring the new code is deployed efficiently and reliably.

Why this answer

AWS CloudFormation detects changes to the `AWS::Lambda::Function` resource's `Code` property only when the properties defined in the template (such as `S3Key` or `S3ObjectVersion`) change. If you upload a new deployment package to S3 using the same bucket and key, CloudFormation will not detect any change and will not update the Lambda function. To resolve this, you should enable S3 Versioning on the bucket, specify the `S3ObjectVersion` in the CloudFormation template, and update this version parameter in the template whenever the code is updated.

Exam trap

Candidates often assume that simply uploading a new deployment package to the same S3 bucket and key will automatically trigger a Lambda update during a CloudFormation stack update. However, CloudFormation does not inspect the contents or hash of the S3 object; it only checks if the template properties themselves have changed. Therefore, you must either change the S3 key or use S3 object versioning and update the version in the template.

How to eliminate wrong answers

Option B is wrong because AWS::Lambda::Version creates a new version of the Lambda function but does not automatically update the function code when the source changes; it only publishes a version of the existing code. Option C is wrong because changing the S3 key alone (without specifying the S3 object version) does not guarantee CloudFormation detects the code change, as CloudFormation compares the S3 object version, not the key, to determine if an update is needed. Option D is wrong because using a custom resource backed by a Lambda function that polls S3 for changes is unnecessarily complex and not the recommended approach; CloudFormation's native S3 object versioning mechanism is the correct and simpler solution.

379
MCQeasy

A company is using AWS CloudFormation to deploy infrastructure. The developer wants to update a stack and needs to know what changes will be made before executing the update. Which AWS CLI command should the developer use?

A.aws cloudformation deploy
B.aws cloudformation create-change-set
C.aws cloudformation validate-template
D.aws cloudformation update-stack
AnswerB

Correct. The aws cloudformation create-change-set command creates a change set, which is a summary of proposed changes to a CloudFormation stack. This allows the developer to review what resources will be added, modified, or deleted before executing the update, without making any actual changes.

Why this answer

The `aws cloudformation create-change-set` command creates a change set, which is a summary of proposed changes to a CloudFormation stack. This allows the developer to review what resources will be added, modified, or deleted before executing the update, without making any actual changes. The change set can then be executed with `aws cloudformation execute-change-set` to apply the changes.

Exam trap

The trap here is that candidates often confuse `aws cloudformation update-stack` with a preview command, but it directly applies changes, whereas `create-change-set` is the correct command for reviewing changes before execution.

How to eliminate wrong answers

Option A is wrong because `aws cloudformation deploy` is used to deploy a stack or update an existing stack directly, but it does not provide a preview of changes before execution; it applies changes immediately. Option C is wrong because `aws cloudformation validate-template` only checks the syntax and structure of a CloudFormation template, not the impact of changes on an existing stack. Option D is wrong because `aws cloudformation update-stack` directly updates the stack without offering a preview of the changes, making it unsuitable for reviewing changes beforehand.

380
MCQeasy

A developer is building a serverless API using Amazon API Gateway and AWS Lambda. The API accepts JSON payloads in the request body. The developer wants to ensure that incoming requests have a valid structure before being passed to the Lambda function to reduce unnecessary invocations. Which API Gateway feature should the developer use?

A.Request validation using models and request validators
B.Usage plans with API keys
C.WAF (AWS WAF) integration
D.Custom authorizer (Lambda authorizer)
AnswerA

API Gateway's request validation feature directly addresses the need to validate the structure and data types of incoming request payloads. By defining a Model, which is essentially a JSON schema, and associating it with a Method's request body, API Gateway automatically checks the request against this schema. Invalid requests, such as those with missing required fields or incorrect data types, are rejected with a 400 Bad Request error *before* the request reaches the backend integration, significantly reducing unnecessary Lambda invocations and operational costs.

Why this answer

API Gateway's request validation feature allows you to define a JSON Schema model for the request body and attach a request validator to the method. This validates the payload structure before the request reaches the Lambda function, preventing invalid payloads from triggering unnecessary invocations and reducing costs.

Exam trap

The trap here is that candidates confuse request validation (payload structure checking) with authorization (who can call the API) or security filtering (WAF), leading them to pick a wrong option like custom authorizer or WAF integration.

How to eliminate wrong answers

Option B is wrong because usage plans with API keys control rate limiting and quota management for API consumers, not payload structure validation. Option C is wrong because AWS WAF integration protects against web exploits like SQL injection or cross-site scripting at the HTTP layer, not JSON schema validation. Option D is wrong because a custom authorizer (Lambda authorizer) authenticates and authorizes the caller (e.g., via OAuth or JWT), but does not validate the request body's structure or content.

381
MCQeasy

The exhibit shows the output of a command. What does this output indicate about the bucket?

A.Versioning is enabled, and MFA delete is required
B.Versioning is suspended
C.Versioning is disabled
D.Versioning is enabled, and MFA delete is not required
AnswerD

This option is correct. The exhibit output confirms that S3 Versioning is `Enabled` for the bucket, which means multiple versions of an object are retained, safeguarding against accidental overwrites or deletions. Furthermore, the output explicitly states that `MFADelete` is `Disabled`, indicating that a multi-factor authentication token is not required to permanently delete an object version or change the bucket's versioning state.

Why this answer

The command output shows `MFA Delete: disabled` and `Versioning: Enabled`. This directly indicates that versioning is enabled on the bucket, but MFA delete is not required. Option D is correct because it matches both displayed fields exactly.

Exam trap

The trap here is that candidates often confuse the `Versioning: Enabled` field with the MFA delete status, incorrectly assuming that versioning being enabled automatically means MFA delete is also enabled, but the two settings are independent.

How to eliminate wrong answers

Option A is wrong because the output explicitly shows `MFA Delete: disabled`, not `enabled`. Option B is wrong because the output shows `Versioning: Enabled`, not `Suspended`. Option C is wrong because the output shows `Versioning: Enabled`, not `Disabled`.

382
MCQhard

A developer is optimizing an S3 bucket for static website hosting. The site has a main page (index.html) and an error page (error.html). Users report seeing a generic 403 error instead of the error page when accessing a missing object. What is the likely cause?

A.The bucket policy denies access to the error.html object.
B.The Error document field in the static website hosting configuration is not set to error.html.
C.The index.html is missing from the bucket.
D.The error.html object has incorrect permissions.
AnswerB

This is the correct answer because the 'Error document' field within the S3 static website hosting configuration explicitly tells S3 which HTML file to serve when a 4xx error occurs. Without this field being correctly set to `error.html`, S3 will not know to redirect error requests to your custom page, even if `error.html` exists and has appropriate permissions. This configuration acts as the crucial routing instruction for custom error handling, ensuring a branded user experience during errors.

Why this answer

When static website hosting is enabled on an S3 bucket, the Error Document field specifies the object served when a 403 or 404 error occurs. If this field is not set to error.html, S3 returns its generic 403 error response instead of the custom error page. The correct answer is B because the Error document configuration is missing or incorrect.

Exam trap

The trap here is that candidates often confuse a permission issue (like a bucket policy or object ACL) with a configuration issue, assuming a 403 error always means 'access denied' rather than a missing Error Document setting.

How to eliminate wrong answers

Option A is wrong because a bucket policy denying access to error.html would cause a 403 error for that specific object, but the scenario describes a generic 403 error when accessing a missing object, not a permission issue on the error page itself. Option C is wrong because if index.html were missing, users would get a 403 or 404 error on the root, but the question specifically states the error occurs when accessing a missing object, not the main page. Option D is wrong because incorrect permissions on error.html would prevent it from being served, but the generic 403 error when accessing a missing object is controlled by the Error Document configuration, not the object's permissions.

383
MCQeasy

A developer wants to store application configuration securely and retrieve it programmatically from EC2 instances. The configuration includes database passwords and API keys. Which AWS service should be used?

A.EC2 user data
B.Amazon S3 with server-side encryption
C.AWS CloudFormation template parameters
D.AWS Systems Manager Parameter Store with SecureString
AnswerD

AWS Systems Manager Parameter Store, specifically when utilizing the SecureString data type, provides a highly secure and scalable solution for storing sensitive application configuration and secrets. SecureString encrypts parameter values using AWS Key Management Service (KMS) customer master keys, ensuring data is protected at rest and in transit. It offers fine-grained IAM access control, versioning, and seamless integration with EC2 instances and other AWS services for secure runtime retrieval without hardcoding credentials.

Why this answer

AWS Systems Manager Parameter Store with SecureString is the correct choice because it is purpose-built for securely storing sensitive configuration data like database passwords and API keys. It integrates with AWS KMS for encryption at rest, supports versioning, and allows EC2 instances to retrieve values via the AWS CLI or SDK using IAM roles, eliminating the need to hardcode secrets.

Exam trap

The trap here is that candidates confuse EC2 user data (which is easy to use but insecure) with a proper secrets management service, overlooking that Parameter Store provides encryption, access control, and audit logging essential for production security.

How to eliminate wrong answers

Option A is wrong because EC2 user data is unencrypted plaintext accessible via the instance metadata service (IMDS) and is intended for startup scripts, not secure storage of secrets. Option B is wrong because while Amazon S3 with server-side encryption protects data at rest, it lacks native integration for programmatic retrieval from EC2 with IAM roles and does not support automatic rotation or versioning of secrets. Option C is wrong because AWS CloudFormation template parameters are used for passing values during stack creation and are not designed for runtime secret retrieval; they can expose secrets in plaintext in the console or logs if not handled carefully.

384
Multi-Selectmedium

A developer is deploying a serverless application using the AWS Serverless Application Model (SAM). The application consists of an API Gateway, Lambda functions, and a DynamoDB table. The developer wants to define and deploy this infrastructure as code. Which files and tools are required? (Choose THREE.)

Select 3 answers
A.Terraform configuration files
B.aws cloudformation deploy command
C.AWS SAM template file (template.yaml)
D.aws cloudformation package command
E.AWS CLI with aws lambda update-function-code command
AnswersB, C, D

The `aws cloudformation deploy` command is the final step in deploying a serverless application defined by an AWS SAM template. It takes the packaged CloudFormation template (which references artifacts uploaded to S3) and creates or updates the entire serverless application stack, including Lambda functions, API Gateway endpoints, and DynamoDB tables, ensuring all resources are provisioned and configured according to the template's specifications.

Why this answer

The AWS SAM template file (template.yaml) is required to define the serverless application resources. The `aws cloudformation package` command uploads local artifacts (such as Lambda deployment packages) to an S3 bucket and returns a copy of the template with references to the S3 object locations. The `aws cloudformation deploy` command then provisions the stack using the processed template.

Together, these three are essential for deploying a SAM application using CloudFormation commands. While SAM CLI provides convenient wrappers like `sam package` and `sam deploy`, the underlying CloudFormation commands can also be used directly.

Exam trap

The trap here is that candidates might think only the SAM template file is enough, but they overlook that the `package` and `deploy` commands are essential to upload artifacts and orchestrate the CloudFormation stack deployment.

385
MCQmedium

A developer is building a serverless application that uses Amazon S3 event notifications to trigger an AWS Lambda function for thumbnail generation. The developer wants to ensure that duplicate S3 events do not cause the same image to be processed multiple times. Which approach should the developer implement to ensure idempotent processing?

A.Store the object key and event ID in a DynamoDB table and check for duplicates before processing
B.Set the Lambda function's concurrency to 1 to prevent concurrent executions
C.Use an Amazon SQS FIFO queue as the event destination
D.Enable S3 event notification filtering based on object size
AnswerA

Amazon S3 event notifications operate on an "at least once" delivery model, meaning duplicate events can occur. By storing a unique identifier, such as a combination of the S3 object key and the event's `eventTime` or a generated `eventId`, in a DynamoDB table, the Lambda function can implement idempotency. Before processing, the function attempts a conditional write to DynamoDB; if the item already exists, it signifies a duplicate event that has been processed or is currently being handled, preventing redundant work and ensuring each object is processed exactly once.

Why this answer

Storing the S3 object key and event ID in a DynamoDB table with a TTL attribute allows the Lambda function to perform a conditional write (or check for an existing item) before processing. This ensures that even if duplicate S3 events are delivered (e.g., due to S3's at-least-once delivery guarantee), the same image is only processed once, achieving idempotency.

Exam trap

The trap here is that candidates often assume S3 event notifications are exactly-once, but the exam tests that they are at-least-once, requiring explicit idempotency handling via an external store like DynamoDB.

How to eliminate wrong answers

Option B is wrong because setting concurrency to 1 only prevents concurrent executions but does not prevent duplicate events from being processed sequentially; the same image could still be processed multiple times if duplicate events arrive one after another. Option C is wrong because SQS FIFO queues provide exactly-once processing within the queue, but S3 event notifications cannot directly send to a FIFO queue (S3 only supports standard SQS queues as event destinations), and even if you manually route through a FIFO queue, the deduplication ID would need to be based on the event ID, which is not automatically handled. Option D is wrong because filtering based on object size only reduces the number of events triggered (e.g., for small or large objects) but does not address duplicate events for the same object; duplicates can still occur regardless of size.

386
MCQeasy

A developer is using AWS SAM to define a serverless application. The application includes an AWS Lambda function that needs to access an Amazon DynamoDB table. The developer wants to grant the Lambda function the minimum required permissions to read and write items in the table. Which resource should the developer use to define the IAM permissions?

A.AWS::DynamoDB::Table
B.AWS::IAM::Role
C.AWS::Serverless::Function Policies property
D.AWS::Lambda::Permission
AnswerC

The Policies property within an AWS::Serverless::Function resource in a SAM template is the designated and most efficient way to attach IAM permissions to the Lambda function's execution role. This property allows developers to specify predefined SAM policy templates (e.g., DynamoDBReadPolicy) or define custom inline IAM policy statements, granting the function the necessary permissions to interact with other AWS services like DynamoDB. It directly modifies the function's execution role to allow specific actions.

Why this answer

The AWS::Serverless::Function resource's Policies property allows you to attach IAM policies directly to the Lambda function's execution role in a declarative manner. By specifying a policy statement with dynamodb:GetItem, dynamodb:PutItem, etc., and the ARN of the DynamoDB table, you grant the minimum required permissions for read and write access without manually creating an IAM role. SAM automatically creates and associates the IAM role with the function, simplifying permission management.

Exam trap

The trap here is that candidates confuse AWS::Lambda::Permission (which controls who can invoke the Lambda) with the IAM permissions needed for the Lambda to access other services, leading them to select Option D instead of the correct Policies property.

How to eliminate wrong answers

Option A is wrong because AWS::DynamoDB::Table defines the DynamoDB table resource itself, not IAM permissions; it cannot grant access to Lambda functions. Option B is wrong because AWS::IAM::Role is a generic CloudFormation resource that requires you to manually define the role, trust policy, and attach policies, which is more verbose and error-prone than using SAM's Policies property. Option D is wrong because AWS::Lambda::Permission is used to grant other AWS services or accounts permission to invoke the Lambda function, not to grant the Lambda function permissions to access other resources like DynamoDB.

387
Multi-Selecthard

A company has a web application running on Amazon ECS with Fargate launch type. The application needs to store and retrieve user session data. The sessions are small and require very low latency access. The development team wants a fully managed solution. Which storage options meet these requirements? (Choose TWO.)

Select 2 answers
A.Amazon DynamoDB
B.Amazon S3
C.Amazon EFS
D.Amazon ElastiCache for Redis
E.Amazon RDS for PostgreSQL
AnswersA, D

Amazon DynamoDB is a fully managed, serverless NoSQL database service that provides consistent single-digit millisecond latency at any scale. Its key-value data model is highly efficient for storing and retrieving session data, which typically involves simple lookups by session ID. DynamoDB's automatic scaling, high availability, and built-in Time-To-Live (TTL) functionality make it an excellent choice for dynamic web application workloads requiring persistent, low-latency session state without operational overhead.

Why this answer

Amazon DynamoDB is correct because it is a fully managed NoSQL key-value database that provides single-digit millisecond latency for read and write operations, making it ideal for storing small session data with low latency requirements. It scales automatically and requires no server management, aligning with the fully managed requirement and the Fargate launch type's serverless nature.

Exam trap

The trap here is that candidates often choose Amazon S3 for its simplicity and low cost, overlooking its higher latency and lack of support for low-latency session storage, or they mistakenly think EFS can be mounted directly to Fargate tasks without understanding the integration limitations.

388
Multi-Selecthard

A company is using AWS CloudFormation to deploy infrastructure. The developer needs to update a stack but wants to avoid downtime for a critical database. Which THREE strategies should the developer consider?

Select 3 answers
A.Set the DeletionPolicy attribute to Retain on the database resource.
B.Use the Parameters section to set a conditional update flag.
C.Use the UpdateReplace policy to create a new resource before deleting the old one.
D.Apply a stack policy that prevents updates to the database resource.
E.Use change sets to review the impact of changes before executing them.
AnswersC, D, E

The UpdateReplacePolicy attribute, when applied to a resource like a database, allows CloudFormation to create a new resource instance before deleting the old one if a property change necessitates replacement. By setting this policy to `Retain` or `Snapshot` (for snapshot-capable resources), CloudFormation ensures the new resource is successfully provisioned and potentially populated or integrated before the original resource is terminated. This strategy significantly minimizes downtime and reduces the risk of data loss during critical database updates, maintaining service continuity.

Why this answer

The `UpdateReplace` policy (specifically using a `CreationPolicy` and `UpdatePolicy` with `AutoScalingReplacingUpdate`) instructs CloudFormation to create a replacement resource before deleting the original, ensuring zero downtime during a stack update that requires resource replacement. This is critical for a database where continuous availability is required.

Exam trap

The trap here is that candidates confuse `DeletionPolicy: Retain` (which only protects against accidental stack deletion) with a mechanism that prevents downtime during updates, when in fact it does nothing to manage the update lifecycle.

← PreviousPage 6 of 6 · 388 questions total

Ready to test yourself?

Try a timed practice session using only Dev AWS Services questions.