AWS Certified Developer – Associate (DVA-C02) flashcards
135 free flashcards. Tap a card to flip it.
Database Bottleneck
Flip cardA database bottleneck occurs when the database cannot handle the volume or complexity of requests, leading to application slowdowns, errors, and connection timeouts.
- Often manifested as high CPU/memory/IOPS on the database.
- Application logs show connection errors or slow queries.
- Can be resolved by scaling the database, optimizing queries, or connection pooling.
Memory trick: When 5xxs strike, follow the request path, starting with the backend.
RDS Vertical Scaling
Flip cardVertical scaling (scaling up) for Amazon RDS involves changing the instance type to one with more CPU, memory, and/or I/O capacity, directly increasing its processing power.
- Addresses bottlenecks due to insufficient compute/memory.
- Requires a brief outage during the instance type change.
- Different from horizontal scaling (read replicas, sharding).
Memory trick: When RDS groans, give it more muscle or fewer tasks.
ALB 503 Service Unavailable
Flip cardAn Application Load Balancer returns a 503 Service Unavailable error when it cannot route a request to a healthy target. This often occurs if the target group has no registered targets or all registered targets fail health checks.
- Indicates ALB cannot find a healthy target.
- Common causes: no registered targets, all targets unhealthy.
- Check target group registration and health check configuration.
Memory trick: Always Look Back for Target Group trouble when you see a 503.
Lambda VPC Timeout
Flip cardLambda functions configured for VPC access can experience timeouts if network connectivity to VPC resources or the internet (via NAT Gateway) is improperly configured, leading to execution hangs.
- Security groups or NACLs can block traffic.
- Subnet routing to NAT Gateway or internet gateway is critical for external access.
- Elastic Network Interface (ENI) creation/deletion overhead can also contribute to cold start latency.
Memory trick: Lambda's network woes often lead to timeout woes.
CloudWatch Alarm Statistics (SQS)
Flip cardCloudWatch alarms based on SQS metrics like 'ApproximateNumberOfMessagesVisible' can behave counter-intuitively if consumers are active. 'ApproximateNumberOfMessagesVisible' counts messages ready for consumption, not messages currently 'in flight' or being processed. An active consumer can keep this metric low even with a large total queue backlog.
- 'Visible' means available to be received.
- Messages 'in flight' are not 'visible'.
- Active consumers reduce 'visible' count.
- Consider 'ApproximateNumberOfMessagesNotVisible' or 'ApproximateNumberOfMessagesDelayed' for total backlog.
Memory trick: SQS 'Visible' messages are like 'Hide-and-Seek'; if the consumer is good, they stay hidden.
Parameter Store KMS Access
Flip cardWhen Systems Manager Parameter Store parameters are encrypted with AWS KMS, the IAM entity accessing them must have `kms:Decrypt` permission on the associated KMS key.
- Separate permission from `ssm:GetParameter`.
- Applies to `SecureString` type parameters.
- KMS key policy can also restrict access.
Memory trick: Parameter Store needs two keys: one for the door, one for the safe.
Container Memory Troubleshooting (Fargate)
Flip cardIn AWS Fargate, container restarts due to memory exhaustion often occur when the container's memory usage exceeds the 'memory' parameter defined in the task definition. This 'memory' parameter sets the hard memory limit, beyond which the container will be killed by the underlying operating system.
- 'memory' defines the hard memory limit.
- 'memoryReservation' is soft limit, for scheduling.
- Exceeding 'memory' causes OOM kills/restarts.
- Check 'MemoryUtilization' metric in Container Insights.
Memory trick: Fargate containers 'Restart' when their 'Memory' is 'Full to the Brim'.
Lambda Account Concurrency Limit
Flip cardAWS Lambda enforces a regional concurrency limit per account, shared across all functions. Exceeding this limit causes `TooManyRequestsException` even if individual function limits are high.
- Default is 1000 concurrent executions per region.
- Can be increased via AWS support request.
- Reserved concurrency protects specific functions from being throttled by others.
Memory trick: Lambda throttling: Check the function, then check the account.
CloudFormation Rollback Failure
Flip cardA CloudFormation stack enters `UPDATE_ROLLBACK_FAILED` when it cannot successfully revert changes during a failed update, leaving it in an inconsistent state.
- Prevents further stack operations.
- Often caused by dependencies, manual changes, or issues with resource deletion.
- `continue-update-rollback` is the primary recovery mechanism.
Memory trick: When CloudFormation's rollback stumbles, 'continue' is the key.
CloudWatch Logs to S3 Permissions
Flip cardTo export CloudWatch Logs to S3, the S3 bucket policy must grant the CloudWatch Logs service principal explicit `s3:PutObject` permission.
- Service principal is `logs.REGION.amazonaws.com`.
- Must be on the *destination* S3 bucket.
- Separate from IAM roles for Lambda/EC2 logging *to* CloudWatch.
Memory trick: CloudWatch Logs needs the S3 bucket's 'permission stamp' to drop off logs.
S3-Lambda Invocation Policy
Flip cardFor S3 to trigger a Lambda function via event notifications, the Lambda function's resource-based policy must explicitly grant S3 permission to invoke it.
- Use `lambda:AddPermission` or configure in console.
- Source ARN must match the S3 bucket triggering the event.
- Prevents unauthorized services from invoking Lambda.
Memory trick: S3 needs a 'permission slip' to talk to Lambda.
CodeBuild Privileged Mode
Flip cardCodeBuild's 'Privileged' flag grants the build environment the ability to run Docker commands, essential for building Docker images or interacting with the Docker daemon.
- Required for `docker build`, `docker run`, etc.
- Enabled in the CodeBuild project settings.
- Not enabled by default for security reasons.
Memory trick: For Docker in CodeBuild, 'Privileged' is the magic word.
Secrets Manager for DB Credentials
Flip cardAWS Secrets Manager securely stores and automatically rotates database credentials (e.g., for RDS) and other secrets. Applications retrieve these secrets at runtime, avoiding hardcoding.
- Secure storage of credentials.
- Automatic rotation for RDS.
- Retrieve secrets at runtime.
- Avoids hardcoding sensitive data.
Memory trick: Secrets Manager rotates DB keys, keeping Lambda code clean.
SQS SSE-KMS
Flip cardServer-Side Encryption with AWS Key Management Service (SSE-KMS) for Amazon SQS encrypts messages at rest using KMS keys. It offers centralized key management, integrates with CloudTrail for auditing, and allows fine-grained access control over keys.
- Encrypts SQS messages at rest.
- Uses AWS KMS for key management.
- Integrates with CloudTrail for key usage auditing.
- Centralized control over key policies.
Memory trick: KMS keys for SQS messages, audited in CloudTrail, centrally managed.
S3 SSE-S3
Flip cardServer-Side Encryption with Amazon S3-Managed Keys (SSE-S3) encrypts S3 objects using keys managed entirely by AWS. S3 handles key creation, rotation, and protection.
- AWS manages the encryption keys.
- Automatic key rotation.
- No customer management of keys required.
- Encrypts data at rest.
Memory trick: S3 Encrypts Safely, Customer Keys or AWS Keys Securely.