AWS Certified Developer – Associate (DVA-C02) practice questions

208 free questions with answers and explanations.

Practice test
  1. 101.A developer is building a backend for a mobile application that needs to synchronize user profile data across multiple devices. The data includes user preferences, game progress, and application settings. The solution must be highly available, scalable, and allow for offline data access with automatic synchronization when the device comes online. Which AWS service is designed to handle this specific requirement?Development with AWS Services
  2. 102.A developer is implementing a feature in an application where users can upload files to an S3 bucket. To ensure data integrity, the application needs to verify that the uploaded file has not been altered during transit. The application calculates the MD5 hash of the file client-side before uploading. How can the developer use S3 to verify the integrity of the uploaded file?Development with AWS Services
  3. 103.A developer is building an application that needs to store confidential user data, such as personally identifiable information (PII), in an Amazon S3 bucket. The data must be encrypted at rest, and the encryption keys must be managed by the developer, with full audit control over key usage. Which S3 encryption option should the developer choose?Development with AWS Services
  4. 104.A company is developing a new serverless application that uses AWS Lambda functions to process user-uploaded files stored in an Amazon S3 bucket. The company requires that all data stored in S3 be encrypted at rest, and the encryption keys must be managed by the customer for compliance reasons. Which S3 encryption option should the developer choose to meet these requirements?Security
  5. 105.A developer is implementing an application that processes highly confidential customer data. This data is stored in an Amazon S3 bucket. The security team requires that all data stored in this S3 bucket must be encrypted at rest using a customer-provided encryption key (SSE-C) to ensure that AWS does not store or manage the encryption keys. How should the developer configure the application to ensure SSE-C is used for all objects uploaded to the S3 bucket?Security
  6. 106.A developer is building a serverless application using AWS Lambda and Amazon DynamoDB. The Lambda function needs to perform read and write operations on a DynamoDB table. To adhere to the principle of least privilege, the developer must grant the Lambda function only the necessary permissions. Which IAM policy action should be included to allow the Lambda function to read a single item from a DynamoDB table, given its primary key?Development with AWS Services
  7. 107.A developer is creating an AWS Lambda function that needs to interact with Amazon S3. The Lambda function will be invoked frequently, and the developer wants to minimize latency by ensuring the S3 client is initialized only once across multiple invocations, rather than on every invocation. How can the developer achieve this?Development with AWS Services
  8. 108.A company is developing an application that requires highly sensitive data to be encrypted both at rest and in transit. For at-rest encryption, they plan to use server-side encryption with customer-provided keys (SSE-C) for objects stored in Amazon S3. For in-transit encryption, they will use SSL/TLS for all communication. What is a key characteristic of SSE-C that the developer must be aware of?Security
  9. 109.A developer is building a new microservice that needs to store persistent user session data for a web application. The data is accessed frequently by a primary key and occasionally by a secondary attribute. The application requires high availability, low-latency access, and the ability to scale to millions of users. Which AWS service is best suited for storing this session data?Development with AWS Services
  10. 110.A developer is building a highly available e-commerce application that needs to store product catalog data. This data is frequently read but updated infrequently. The application requires very low read latency (single-digit milliseconds) and must be able to scale to millions of reads per second. Data consistency is eventually consistent, which is acceptable for product catalog data. Which AWS service is the most cost-effective and performant solution for this use case?Development with AWS Services
  11. 111.A developer is building a serverless application that uses AWS Lambda functions. The application experiences occasional cold starts, leading to increased latency for initial requests, especially during peak traffic hours. To mitigate this issue and ensure consistent low latency for all invocations, which Lambda configuration should the developer enable?Development with AWS Services
  12. 112.A developer is investigating an issue where an AWS Fargate service running a Docker container intermittently crashes and restarts. CloudWatch Container Insights metrics show that the service's memory utilization frequently spikes to 95% or more before the crashes, even though the container's `memoryReservation` is set to 512MB and `memoryLimit` to 1024MB. The application logs indicate no specific errors before the crash, only sudden termination. Which of the following is the MOST effective approach to diagnose and resolve this issue?Troubleshooting and Monitoring
  13. 113.A developer is building an application that uses Amazon SQS. Messages sent to the queue contain sensitive customer data. The developer needs to ensure that these messages are encrypted at rest within the SQS queue. Which feature should be enabled to meet this requirement?Security
  14. 114.A developer is implementing a new microservice that needs to send email notifications to users. The application requires a highly available, scalable, and cost-effective email sending service that can integrate easily with AWS. The emails contain dynamic content generated by the microservice. Which AWS service should the developer use?Development with AWS Services
  15. 115.A client is developing an application that uses Amazon S3 to store large video files, some exceeding 100 GB. The application frequently updates these files, often modifying only small portions. The client needs to ensure data integrity and efficient updates. Which S3 feature should the developer use to upload these large files while allowing for resumable uploads and part-level integrity checks?Development with AWS Services
  16. 116.A developer is building a web application that uses Amazon API Gateway to expose RESTful APIs. User authentication for this application is handled by Amazon Cognito User Pools. The developer needs to secure the API Gateway endpoints so that only authenticated users from the Cognito User Pool can invoke them. Which type of API Gateway authorizer should the developer use?Security
  17. 117.A developer is implementing a new feature for an existing application that involves processing a large number of independent tasks. Each task can take a variable amount of time (from seconds to minutes) and needs to be processed in a fault-tolerant manner, even if the primary processing instance fails. The application should be able to scale horizontally to handle varying loads. Which AWS service is MOST appropriate for orchestrating and managing these tasks?Development with AWS Services
  18. 118.A developer is building a new microservice that needs to asynchronously process messages from other services. The messages are critical and must not be lost if the consuming service experiences a temporary outage or overload. The developer needs to ensure that messages are delivered at least once and that the consuming service can scale independently based on the message backlog. Which AWS service should the developer choose to meet these requirements?Development with AWS Services
  19. 119.A developer is building a web application that needs to store persistent user session data. The application requires very low latency access (single-digit milliseconds) to this data, and it must be highly available and scalable to handle millions of concurrent users. The session data is frequently read and written. Which AWS service is the MOST appropriate choice for this use case?Development with AWS Services
  20. 120.A developer is creating a new application that needs to securely communicate with an Amazon RDS PostgreSQL database instance. The application requires that all data exchanged between the application and the database is encrypted in transit. The application is deployed on an EC2 instance within the same VPC as the RDS instance. Which configuration should the developer implement to ensure in-transit encryption?Security
  21. 121.A developer is building a web application that uses Amazon API Gateway to expose a REST API. The API needs to invoke an AWS Lambda function. The Lambda function's execution role has the necessary permissions to perform its tasks. However, when testing the API, the developer receives a '500 Internal Server Error' from API Gateway, and CloudWatch Logs show 'Missing Authentication Token' errors originating from API Gateway, even though the Lambda function itself runs successfully when invoked directly. What is the MOST likely cause of this issue?Development with AWS Services
  22. 122.A developer is designing a serverless application that processes a high volume of real-time clickstream data from a website. The data needs to be ingested continuously, and multiple downstream applications (e.g., real-time analytics, archival to S3, and a dashboard) need to consume this data concurrently and independently. The solution must support ordering of records and allow for replay of data for a limited time. Which AWS service should the developer use as the ingestion and streaming layer?Development with AWS Services
  23. 123.A developer is building a new microservice that needs to store and retrieve unstructured JSON documents with millisecond latency. The data access patterns are highly variable, and the application requires automatic scaling to handle unpredictable traffic spikes. Which AWS service is the MOST appropriate for this use case?Development with AWS Services
  24. 124.A developer is building a serverless application that uses AWS Lambda functions to process user requests. The application needs to store temporary, per-request data that can be accessed by subsequent invocations of the same Lambda function instance within a short period. The data does not need to persist beyond the lifetime of a single function instance or between different instances. Which AWS service is the MOST cost-effective and performant solution for storing this temporary data?Development with AWS Services
  25. 125.A developer is building a new application that uses AWS Lambda functions to process sensitive customer data. The Lambda functions need to store temporary state information that is specific to each user session and must be highly secure. This data should not persist beyond the session and must be encrypted at rest and in transit. Which AWS service is the MOST appropriate for securely storing this temporary, session-specific data?Security
  26. 126.A developer is designing an application that processes highly confidential customer data. The data needs to be encrypted at rest on Amazon EBS volumes attached to EC2 instances. The company requires full control over the encryption keys and wants to ensure that the keys are regularly rotated. Which encryption option should the developer choose for the EBS volumes?Security
  27. 127.A developer is writing an AWS Lambda function that needs to make HTTP requests to an external API. The external API requires a static IP address for whitelisting purposes. The Lambda function is currently deployed inside a VPC, but it does not have direct internet access. How can the developer configure the Lambda function to meet this requirement?Development with AWS Services
  28. 128.A developer is building a web application using AWS Elastic Beanstalk. The application needs to store sensitive configuration parameters, such as database connection strings and API keys, securely. These parameters should not be hardcoded in the application and should be easily updated without redeploying the application. Which AWS service is best suited for managing these application parameters?Development with AWS Services
  29. 129.A developer is building a new application that will use Amazon S3 to store publicly accessible static website content, such as HTML, CSS, JavaScript, and images. While the content itself should be publicly readable, the S3 bucket should prevent unauthorized users from performing actions like deleting objects or modifying bucket configurations. Which S3 access control mechanism is MOST appropriate for this scenario?Security
  30. 130.A developer is designing a new microservice that needs to handle a high volume of real-time sensor data from IoT devices. The data needs to be ingested, processed, and then stored in a data lake for analytics. The solution must support multiple consumers reading the same data stream concurrently and guarantee the order of records within each shard. Which AWS service is best suited for the ingestion and streaming of this data?Development with AWS Services
  31. 131.A developer is building an application that integrates with a third-party service. This service requires a static IP address for its allowlist to permit incoming connections. The application will run on AWS Lambda functions in a VPC. How can the developer ensure that the Lambda functions access the third-party service from a consistent, static IP address?Security
  32. 132.A developer is building a serverless application using AWS Lambda and Amazon API Gateway. The Lambda functions need to interact with an Amazon RDS PostgreSQL database instance. The database credentials (username and password) must be rotated regularly and never hardcoded in the Lambda function code. Which approach provides the MOST secure and automated way to manage and access these database credentials?Security
  33. 133.A developer is designing a microservices architecture where services communicate asynchronously via Amazon SQS. Sensitive customer data will be transmitted through these SQS queues. The security team requires that all messages in transit and at rest within SQS must be encrypted. Furthermore, the encryption keys must be centrally managed and auditable. Which SQS encryption option should the developer implement?Security
  34. 134.A developer is building a new microservice that needs to store session data for web users. This data must be highly available, low-latency, and capable of handling millions of requests per second. The session data is simple key-value pairs and does not require complex querying or relational integrity. Which AWS service should the developer choose to meet these requirements?Development with AWS Services
  35. 135.A startup is developing a new social media application that needs to store large volumes of user-uploaded images and videos in Amazon S3. The application requires granular access control to these objects, where only the uploading user can access their own files, and administrators can access all files. The application backend runs on AWS Lambda. How can the developer implement this access control MOST effectively and securely?Security
  36. 136.A developer is building a mobile application that needs to authenticate users using social identity providers (e.g., Facebook, Google) and then grant them access to AWS resources. The application requires temporary, limited-privilege credentials for users to interact with services like Amazon S3 and DynamoDB directly from the mobile client. Which AWS service combination should the developer use to achieve this?Security
  37. 137.A developer is writing an application that processes a high volume of sensor data from IoT devices. Each data point needs to be ingested in real-time, and multiple downstream services need to consume this data concurrently for different purposes (e.g., analytics, anomaly detection, archival). The solution must be highly scalable and provide ordered processing within each data stream. Which AWS service is best suited for this ingestion and distribution?Development with AWS Services
  38. 138.A developer is building a new serverless application using AWS Lambda functions. This application needs to securely interact with a third-party API that requires a static egress IP address for whitelisting purposes. How can the developer ensure that the Lambda functions always use a static egress IP address?Security
  39. 139.A developer is creating a mobile application that needs to authenticate users and provide them with temporary, limited-privilege AWS credentials to directly access AWS services like Amazon S3 for uploading user-generated content. The application also needs to support authentication with social identity providers (e.g., Google, Facebook). Which AWS service should the developer use to manage user identities and issue temporary AWS credentials?Development with AWS Services
  40. 140.A developer is building a mobile application that uses Amazon API Gateway to expose a backend Lambda function. The application needs to ensure that only authenticated users from a Cognito User Pool can invoke the API Gateway endpoint. Which authorization type should the developer configure for the API Gateway method?Security
  41. 141.A developer is writing an AWS Lambda function that processes images uploaded to an Amazon S3 bucket. The Lambda function needs to perform image resizing, apply watermarks, and then store the modified images in another S3 bucket. This process involves downloading the original image, processing it locally within Lambda, and then uploading the result. Which of the following is the most efficient way for the Lambda function to handle the temporary storage of image files during processing?Development with AWS Services
  42. 142.A developer is building a serverless application that processes sensitive user data. The application uses AWS Lambda functions and stores data in Amazon S3. To meet compliance requirements, all data at rest in S3 must be encrypted using a customer-managed key (CMK) from AWS Key Management Service (KMS). How can the developer ensure that all objects uploaded to a specific S3 bucket are encrypted using the desired KMS CMK, and prevent unencrypted uploads?Development with AWS Services
  43. 143.A developer is creating a new AWS Lambda function that needs to access a private Amazon RDS PostgreSQL database instance within a VPC. The Lambda function is configured with the correct VPC, subnets, and security groups. However, when the Lambda function attempts to connect to the database, it times out. Other EC2 instances in the same subnets can connect to the database without issues. What is the MOST likely cause of the Lambda function's connection failure?Troubleshooting and Monitoring
  44. 144.A developer has configured an Amazon Kinesis Data Stream with 5 shards. A Lambda function is consuming events from this stream. Recently, the developer noticed that the 'IteratorAgeMilliseconds' metric for the Lambda function consuming from this stream is steadily increasing, reaching several hours. The Lambda function's 'Errors' and 'Throttles' metrics are low, and its invocation duration is stable and low (under 100ms). What is the MOST likely cause of the increasing 'IteratorAgeMilliseconds'?Troubleshooting and Monitoring
  45. 145.A company is migrating an on-premises application to AWS. The application uses a custom identity provider (IdP) for user authentication. The development team needs to integrate this custom IdP with AWS to allow authenticated users to assume IAM roles and access AWS resources directly (e.g., upload files to an S3 bucket). Which AWS service should be used to facilitate this federation?Security
  46. 146.A developer is building a serverless application that needs to execute long-running batch jobs (up to 15 minutes) that process large datasets stored in Amazon S3. The jobs are triggered by S3 object creation events and require significant computational resources. The developer wants to minimize operational overhead and pay only for the compute time consumed. Which AWS service is the most appropriate for executing these batch jobs?Development with AWS Services
  47. 147.A developer is creating a serverless API using Amazon API Gateway and AWS Lambda. The API needs to handle varying loads, from zero requests per second to thousands of requests per second, with minimal cold start latency for the Lambda functions. The developer wants to ensure that a certain number of Lambda execution environments are always initialized and ready to respond instantly. Which Lambda feature should be configured?Development with AWS Services
  48. 148.A developer is creating an application that needs to grant temporary, limited-privilege access to AWS resources for unauthenticated users. These users will interact with a public web application and occasionally upload files to an S3 bucket. Which AWS service should the developer use to facilitate this access model?Security
  49. 149.A developer needs to implement a highly available and scalable backend for a web application using serverless technologies. The application will receive HTTP requests, process them using a Lambda function, and store data in a NoSQL database. The solution must handle unpredictable traffic spikes without manual intervention. Which architecture component should be used to expose the Lambda function as an HTTP endpoint?Development with AWS Services
  50. 150.A global company is deploying a new web application that needs to authenticate users from various social identity providers (e.g., Facebook, Google) and corporate directories (e.g., SAML 2.0). After authentication, the application needs to grant these users temporary, limited-privilege access to AWS resources (e.g., upload files to S3). Which combination of AWS services should the developer use to fulfill both authentication and authorization requirements?Security