AWS Certified Developer – Associate (DVA-C02) practice questions
208 free questions with answers and explanations.
- 51.A developer is building a serverless application that uses AWS Lambda to process images uploaded to an Amazon S3 bucket. The Lambda function needs to download the original image, resize it, and then upload the resized image back to S3. The image resizing library requires temporary disk space to store intermediate files during processing. Which of the following is the MOST efficient and secure way for the Lambda function to handle these temporary files?Development with AWS Services
- 52.A Lambda function processes messages from an SQS queue. Developers notice that sometimes messages are processed multiple times, even though the function successfully completes its execution for each message. The Lambda function's concurrency is set to 100, and the SQS queue's visibility timeout is 30 seconds. The Lambda function typically takes 5-10 seconds to process a message. What is the MOST likely reason for the duplicate processing?Troubleshooting and Monitoring
- 53.A company is developing a new serverless application using AWS Lambda functions. This application needs to retrieve database credentials, API keys, and other sensitive configuration parameters at runtime. The security team insists on a solution that provides centralized storage for secrets, automatic rotation, and fine-grained access control. Which AWS service is BEST suited for this requirement?Security
- 54.A developer is building an API using Amazon API Gateway that needs to securely expose an endpoint to a partner company. The partner company requires that all requests to the API be authenticated using their existing custom authentication system, which provides a JWT token. The developer needs to validate this JWT token before forwarding requests to the backend Lambda function. Which API Gateway authorization method should the developer implement?Security
- 55.A developer is deploying a containerized application to Amazon ECS Fargate. The application needs to perform operations on an Amazon S3 bucket and publish messages to an Amazon SNS topic. The security team has mandated that the application should not use static AWS credentials and must adhere to the principle of least privilege. How can the developer provide the necessary permissions to the Fargate task securely?Security
- 56.A developer is building a new application that needs to call an external third-party API that requires requests to originate from a static, known IP address for security whitelist purposes. The application runs on AWS Lambda functions in a VPC. How can the developer configure the Lambda functions to meet this requirement?Security
- 57.A developer is building a new application that processes financial transactions. Each transaction must be processed exactly once, even if the processing system experiences failures or retries. The application uses an Amazon SQS queue for incoming transactions. Which SQS queue type should the developer use to guarantee exactly-once processing?Development with AWS Services
- 58.A development team is building a new application that will use Amazon RDS for its database. The security team has mandated that all connections to the RDS database must be encrypted in transit. The application will be deployed on EC2 instances within the same VPC as the RDS instance. How can the developer ensure that the application uses SSL/TLS for all connections to the RDS database?Security
- 59.A developer is building a high-throughput, low-latency data ingestion pipeline. The application needs to process millions of small records per second from various sources and then perform real-time analytics. The data needs to be ordered and durable. Which AWS service is BEST suited for capturing and persisting this streaming data?Development with AWS Services
- 60.A developer is building a serverless application that processes large files uploaded to an S3 bucket. The processing logic is implemented as an AWS Lambda function. The Lambda function needs to be triggered automatically whenever a new file is uploaded to the S3 bucket. Which of the following is the MOST efficient way to configure this trigger?Development with AWS Services
- 61.A developer is building an application that needs to securely store and retrieve binary files, such as images and videos. These files are frequently accessed, and the application requires high durability and availability. Which AWS service is the MOST appropriate for storing these files?Development with AWS Services
- 62.A developer is building an application that needs to publish real-time notifications to multiple subscribers over different protocols (e.g., SMS, email, HTTP/S endpoints, Lambda functions). The application should not be aware of the specific delivery mechanisms or subscriber details, promoting loose coupling. Which AWS service is best suited for this publish-subscribe messaging pattern?Development with AWS Services
- 63.A developer is building a new application that needs to access an Amazon S3 bucket. The security team has mandated that access to the S3 bucket must be restricted to specific IAM roles and that all data transfers to and from S3 must occur over private AWS networks, without traversing the public internet. Which two configurations are required to meet these security requirements?Security
- 64.A developer is implementing a feature for an existing application that involves processing a series of asynchronous steps. Each step has different dependencies and failure conditions, and the overall process needs robust error handling, retry mechanisms, and the ability to track the state of each execution. The developer wants to avoid complex orchestration code in a single Lambda function. Which AWS service is best suited for this workflow orchestration?Development with AWS Services
- 65.A developer is building an application that needs to retrieve temporary security credentials to make programmatic calls to AWS services. The application is running on an EC2 instance. Which mechanism should the developer use to obtain these credentials securely without embedding them in the application code or configuration files?Security
- 66.A development team is deploying a new microservice on AWS Fargate. This microservice needs to access an Amazon RDS PostgreSQL database. The security team has mandated that all connections to the database must be encrypted using SSL/TLS to protect data in transit. How can the developer ensure that the Fargate task establishes an SSL/TLS encrypted connection to the RDS database?Security
- 67.A developer needs to create an AWS Lambda function that retrieves secrets from AWS Secrets Manager. The Lambda function will be invoked by an API Gateway endpoint. What is the MINIMUM set of permissions required for the Lambda execution role to allow it to retrieve a specific secret named 'MyDatabaseSecret' from Secrets Manager?Security
- 68.A developer is building a high-performance, real-time analytics application that processes a continuous stream of financial transaction data. The application requires extremely low-latency data ingestion and the ability to process data at massive scale (hundreds of thousands of records per second). The data needs to be available for multiple consumers simultaneously for different analytical purposes. Which AWS service is BEST suited for this scenario?Development with AWS Services
- 69.A developer is building a mobile application that needs to retrieve images stored in an Amazon S3 bucket. The images are highly sensitive and should only be accessible for a limited time after a user requests them. The application should not expose AWS credentials to the mobile client. Which is the most secure way to grant temporary access to these S3 objects?Security
- 70.A developer is building a serverless application using AWS Lambda and Amazon SQS. The Lambda function processes messages from an SQS queue. If the Lambda function fails to process a message after multiple retries, the developer wants to ensure the message is moved to a separate queue for later investigation, rather than being discarded. What SQS feature should the developer configure to achieve this?Development with AWS Services
- 71.A developer needs to store sensitive configuration data, such as database credentials and API keys, for an application deployed on AWS. This data should be accessible by EC2 instances and Lambda functions, encrypted at rest, and support versioning for auditing purposes. Which AWS service is BEST suited for this requirement?Development with AWS Services
- 72.A developer is building an application that needs to securely send messages between microservices using Amazon SQS. The messages contain sensitive customer information and must be protected from unauthorized access while in transit and at rest within the queue. The company's security policy dictates that all encryption keys must be rotated automatically and managed by AWS. Which SQS encryption option should the developer choose?Security
- 73.A developer is building a serverless application using AWS Lambda and Amazon DynamoDB. The Lambda function performs frequent read and write operations to a DynamoDB table. During peak load, the developer observes `ProvisionedThroughputExceededException` errors from DynamoDB. The table is configured in 'On-demand' capacity mode. What is the MOST likely cause of these exceptions?Troubleshooting and Monitoring
- 74.A developer is troubleshooting an AWS Step Functions state machine that invokes a Lambda function. The state machine is failing with `Lambda.Unknown` errors, but the Lambda function's CloudWatch logs show successful executions with no errors. The Step Functions execution history shows the `Lambda.Unknown` error occurring immediately after the Lambda task state starts. What is the MOST likely root cause of this `Lambda.Unknown` error?Troubleshooting and Monitoring
- 75.A developer is building a new serverless application that uses AWS Lambda functions to process data. This application needs to securely store and retrieve database credentials and API keys. The security team has mandated that secrets must be automatically rotated and audited. Which AWS service should the developer use to meet these requirements?Security
- 76.A developer is creating an AWS Lambda function that needs to retrieve a secret from AWS Secrets Manager. To avoid hardcoding the secret and ensure secure access, the developer should use the AWS SDK within the Lambda function. Which of the following code snippets (pseudo-code) demonstrates the correct way to retrieve a secret named 'MyDatabaseSecret' using the AWS SDK for Python (Boto3)?Development with AWS Services
- 77.A developer is building a web application that authenticates users using Amazon Cognito User Pools. After successful authentication, the application needs to access AWS resources, such as an Amazon S3 bucket, on behalf of the authenticated user. What is the most secure and recommended way for the application to obtain temporary, limited-privilege credentials for accessing these AWS resources?Security
- 78.A development team is using AWS CodeBuild for their continuous integration pipeline. Recently, builds have started failing with an 'Out of memory' error during the compilation phase, even though the source code size has not significantly increased. The build project is configured with a 'build.general1.small' compute type. What is the MOST efficient solution to resolve this issue?Troubleshooting and Monitoring
- 79.A developer is building a new application that needs to securely store temporary data generated by users. This data should only be accessible by the user who created it and must expire automatically after a short period. The data is not highly sensitive but requires isolation per user. Which AWS service and access pattern should be used?Security
- 80.A developer is designing an application that requires users to upload large files (up to 100 GB) to an Amazon S3 bucket. To ensure robust uploads, the application must be able to resume uploads after network interruptions and improve overall upload speed by uploading parts of the file concurrently. Which S3 API operation should the developer use to meet these requirements?Development with AWS Services
- 81.A developer is building a RESTful API using Amazon API Gateway. The API needs to restrict access to specific users who have authenticated through a custom identity provider. The solution must ensure that only authenticated users with valid tokens can invoke the API methods. Which API Gateway authorizer type should be implemented?Security
- 82.A developer is creating an AWS Lambda function that processes incoming messages from an Amazon SQS queue. The function occasionally fails to process certain messages due to transient issues with a downstream service. The developer wants to ensure that these failed messages are automatically retried and, if still unsuccessful after several attempts, moved to a separate queue for manual inspection. Which SQS feature should the developer implement?Development with AWS Services
- 83.A developer is building a serverless application using AWS Lambda and Amazon DynamoDB. The Lambda function needs to perform `PutItem` operations on a DynamoDB table. To ensure secure and efficient access, how should the developer grant the Lambda function permissions to access DynamoDB?Development with AWS Services
- 84.A development team is building a new web application that uses Amazon API Gateway to expose RESTful APIs. This application needs to integrate with an existing identity provider (IdP) that supports the OpenID Connect (OIDC) standard. Which API Gateway authorizer type should the developer choose to authenticate users from this IdP?Security
- 85.A financial services company is developing a new serverless application using AWS Lambda functions and Amazon DynamoDB. The application will store highly sensitive customer financial data in DynamoDB. The compliance team has mandated that all data at rest in DynamoDB must be encrypted, and the encryption keys must be managed by the customer with full control over key rotation and access policies. Which encryption option should the developer choose for DynamoDB?Security
- 86.A developer is writing an AWS Lambda function that needs to access resources in a private Amazon VPC, such as an Amazon RDS database. The Lambda function is currently configured to run outside of a VPC. What is the MINIMUM change required to allow the Lambda function to securely access the RDS database?Development with AWS Services
- 87.A developer is building a serverless application using AWS Lambda and Amazon API Gateway. The Lambda function needs to access a database hosted in a private subnet within a Virtual Private Cloud (VPC). The developer has configured the Lambda function to run within the VPC. However, the Lambda function also needs to make outbound calls to third-party APIs on the internet. Which additional networking component is required to allow the Lambda function to reach the internet while remaining in the private subnet?Development with AWS Services
- 88.A developer is implementing a feature where an AWS Lambda function needs to make HTTP requests to an external API over the internet. The Lambda function is configured to run within a private VPC subnet for security reasons, without direct internet access. What is the MOST appropriate and secure way to allow the Lambda function to access the external API?Development with AWS Services
- 89.A developer is creating a mobile application that requires users to authenticate using their social media accounts (e.g., Facebook, Google) and also supports traditional email/password sign-up. The application needs to securely manage user profiles and provide temporary, limited-privilege access to AWS resources (e.g., S3 for user content). Which AWS service is the most suitable for managing user authentication, authorization, and identity federation?Development with AWS Services
- 90.A developer is building a web application that needs to securely store configuration data, such as database connection strings and environment variables. This data must be encrypted at rest and easily retrievable by the application. The solution should also support versioning of the configuration data. Which AWS service is best suited for this purpose?Security
- 91.A developer has deployed a new web application on AWS using Amazon EC2 instances behind an Application Load Balancer (ALB). Users are reporting intermittent 504 Gateway Timeout errors. The EC2 instances are running Amazon Linux 2, and the application logs show no errors at the time of the 504s. CloudWatch metrics for the EC2 instances show CPU utilization below 30% and sufficient free memory. Which of the following is the MOST likely cause of these 504 errors?Troubleshooting and Monitoring
- 92.A development team is deploying a new microservice on AWS Fargate. This microservice needs to interact with an Amazon RDS database instance. To ensure secure communication, the team wants to implement encryption in transit between the Fargate task and the RDS instance. Which configuration should the developer apply?Security
- 93.A developer is creating a mobile application that needs to authenticate users using their social identity providers (e.g., Google, Facebook) and then grant them access to specific AWS resources. The developer wants to avoid managing user credentials directly within the application or in a custom database. Which AWS service combination should be used to achieve this securely and efficiently?Security
- 94.A developer has implemented AWS CloudWatch alarms for an Amazon SQS queue. The alarms are configured to trigger when `NumberOfMessagesSent` exceeds a threshold, indicating high producer activity. However, during recent load tests, the SQS queue was flooded with messages, but the `NumberOfMessagesSent` alarm did not trigger. Other SQS metrics like `ApproximateNumberOfMessagesVisible` correctly show a large number of messages. What is the MOST probable reason the alarm did not trigger?Troubleshooting and Monitoring
- 95.A developer is implementing an AWS Lambda function that processes images uploaded to an Amazon S3 bucket. The function needs to resize the images and store the resized versions in another S3 bucket. The developer wants to ensure that the Lambda function only has the necessary permissions to read from the source S3 bucket and write to the destination S3 bucket. Which IAM policy principle should be applied?Development with AWS Services
- 96.A developer is building a mobile application that needs to securely store user-specific data in a NoSQL database. Each user should only be able to access and modify their own data. The application uses Amazon Cognito for user authentication. Which AWS service and configuration should the developer use to store this data while enforcing fine-grained access control based on the authenticated user?Security
- 97.A developer is building a new application that uses Amazon S3 to store confidential customer data. The security team has mandated that all data stored in S3 must be encrypted at rest, and the encryption keys must be managed by the customer. The solution should also allow the customer to audit the usage of these encryption keys. Which S3 encryption option meets these requirements?Security
- 98.A developer is building an application that needs to retrieve sensitive configuration parameters, such as API keys and database connection strings, from AWS Systems Manager Parameter Store. The Lambda function retrieving these parameters is configured with an IAM role. For maximum security, how should the developer retrieve these parameters, ensuring they are decrypted automatically if encrypted?Development with AWS Services
- 99.A developer is building a new serverless application using AWS Lambda and Amazon API Gateway. The application needs to securely store and retrieve sensitive configuration parameters, such as database connection strings and API keys, without hardcoding them into the Lambda function code. The developer wants to ensure that these parameters are encrypted at rest and in transit, and that access is strictly controlled. Which AWS service is the most appropriate for this requirement?Security
- 100.A developer is building a backend for a mobile application that needs to synchronize user profile data across multiple devices. The data includes user preferences, game progress, and application settings. The solution must be highly available, scalable, and allow for offline data access with automatic synchronization when the device comes online. Which AWS service is designed to handle this specific requirement?Development with AWS Services