AWS Certified Developer – Associate (DVA-C02) practice questions
208 free questions with answers and explanations.
- 151.A developer is creating a new serverless application using AWS Lambda and Amazon API Gateway. The Lambda function needs to retrieve a secret (e.g., a database password) from AWS Secrets Manager. The security team insists on the principle of least privilege. What is the MINIMUM IAM permission required for the Lambda function's execution role to retrieve a specific secret named `prod/my_app/db_password` from Secrets Manager?Security
- 152.A developer is deploying a containerized application to Amazon ECS Fargate. The application needs to interact with other AWS services, such as DynamoDB and SQS. The developer wants to ensure that the application has only the necessary permissions and that credentials are not hardcoded. How should the developer securely grant permissions to the Fargate tasks?Security
- 153.A developer is building a sensitive microservice that processes payment information. This microservice runs on AWS Fargate and needs to store encrypted temporary data at rest on its local storage for processing, which is ephemeral and automatically deleted when the task stops. The data must be encrypted using a customer-managed key (CMK) from AWS KMS. How can the developer ensure this temporary data is encrypted with a CMK?Security
- 154.A financial services company is developing a new serverless application using AWS Lambda functions. This application will process highly sensitive customer financial data and store it in an Amazon DynamoDB table. The security team has a strict requirement that all data at rest in DynamoDB must be encrypted using a customer-managed key (CMK) from AWS Key Management Service (KMS) for enhanced control and auditability. How can the developer ensure DynamoDB uses a specific KMS CMK for encryption at rest?Security
- 155.A developer is writing an AWS Lambda function that needs to interact with Amazon DynamoDB. The function requires permissions to perform 'PutItem' and 'UpdateItem' actions on a specific DynamoDB table named 'ProductCatalog'. Which of the following IAM policy statements should be attached to the Lambda function's execution role to grant the MINIMUM necessary permissions?Development with AWS Services
- 156.A developer is creating a new application that uses AWS Lambda functions to process data. The application needs to interact with an Amazon RDS PostgreSQL database instance. To ensure secure and efficient database connections, the developer wants to leverage a fully managed service that handles connection pooling, multiplexing, and automatic credential rotation. Which AWS service should the developer use?Development with AWS Services
- 157.A global company is deploying a new web application that needs to authenticate users from various identity providers, including corporate directories (via SAML) and social media accounts (e.g., Google, Apple). The application must then grant these authenticated users temporary, federated access to specific AWS resources. What is the MOST suitable AWS service to manage both authentication from these diverse sources and authorization to AWS resources?Security
- 158.A developer has implemented a new feature in an application that involves uploading large files (up to 5GB) to an S3 bucket using presigned URLs from an EC2 instance. Users are reporting occasional 'Access Denied' errors during the upload process, even though the IAM role attached to the EC2 instance has `s3:PutObject` permissions for the target bucket. The presigned URLs are generated correctly with an expiration of 15 minutes. What is the MOST probable cause of the 'Access Denied' errors?Troubleshooting and Monitoring
- 159.A developer is creating an application that needs to securely upload large files (up to 50 GB) to Amazon S3. To improve reliability and performance, especially over unreliable networks, the developer wants to use multipart uploads. What is the MINIMUM part size allowed for all parts except the last part when performing a multipart upload to S3?Development with AWS Services
- 160.A developer is building a web application that uses Amazon RDS for its database. The application is containerized and deployed on AWS Fargate, scaling dynamically based on traffic. The developer observes that during periods of rapid scaling, new containers struggle to establish database connections quickly, sometimes leading to connection errors. They also want to manage database credentials more securely without embedding them directly in the application code. Which AWS service can help address both these issues?Development with AWS Services
- 161.A developer is designing an application where multiple microservices need to communicate asynchronously without direct coupling. Each microservice publishes messages about its state changes, and other microservices need to react to these specific messages. The solution must support fan-out to multiple subscribers and ensure message durability. Which AWS service combination is BEST suited for this scenario?Development with AWS Services
- 162.A development team is deploying a new web application on Amazon EC2 instances that needs to securely interact with other AWS services, such as Amazon S3 and Amazon DynamoDB, without embedding AWS access keys directly into the application code. The application runs on EC2 instances within a private subnet. Which method should the team use to grant these EC2 instances temporary, limited-privilege access to AWS resources?Security
- 163.A company uses AWS X-Ray to trace requests through a microservices architecture. A developer notices that traces are incomplete, showing only the initial service and the final database call, but missing segments from an intermediate Lambda function that processes data before calling the database. The Lambda function is invoked by an SQS queue. What is the MOST likely reason for the missing Lambda segments?Troubleshooting and Monitoring
- 164.A developer is building an application that needs to store confidential user data, such as personally identifiable information (PII). The data must be encrypted at rest and in transit, and access to the decryption keys must be strictly controlled and audited. Which AWS service combination provides the most secure and compliant solution for storing and managing the encryption keys?Development with AWS Services
- 165.A developer is building an application that uses Amazon SQS for message queuing. The messages contain sensitive customer information. The security team requires that all messages at rest within the SQS queues must be encrypted. The solution should also allow for auditability of key usage. Which SQS encryption option should the developer choose to meet these requirements?Security
- 166.A developer is building a mobile application that needs to securely store user-specific data (e.g., application settings, high scores) in the cloud. Each user should only be able to read and write their own data. The application uses Amazon Cognito for user authentication. Which AWS service, combined with Cognito, is the MOST appropriate for storing this user-specific data with granular access control?Security
- 167.A developer is implementing a new feature where an AWS Lambda function needs to send emails to users. The application requires the ability to send emails to verified identities and manage email templates. Which AWS service should the developer integrate with the Lambda function to achieve this functionality?Development with AWS Services
- 168.A developer is building a mobile application that needs to securely store user-specific configuration settings and preferences. These settings should be synchronized across multiple devices for the same user and remain available even if the device is offline. Which AWS service is BEST suited for this requirement?Development with AWS Services
- 169.A developer is writing an AWS Lambda function that processes messages from an Amazon SQS queue. The function is occasionally failing due to external API rate limits. The developer wants to ensure that failed messages are automatically retried with an exponential backoff strategy without writing custom retry logic in the Lambda function. What is the most efficient way to achieve this?Development with AWS Services
- 170.A developer is observing high latency and occasional 5xx errors from an API Gateway endpoint that integrates with a Lambda function. CloudWatch metrics for the Lambda function show low invocation errors, average duration well within limits, and sufficient concurrency. However, API Gateway's 'Latency' metric is high, and the '5XXError' metric is elevated. The Lambda function logs show successful executions for all triggered events. Which of the following is the MOST likely cause of the API Gateway errors and latency spikes?Troubleshooting and Monitoring
- 171.A developer is building a high-performance web application that uses Amazon DynamoDB for its core data store. To improve read latency and reduce the load on the primary DynamoDB table, the developer wants to implement a caching layer that is fully managed and compatible with DynamoDB's API. Which AWS service should the developer choose?Development with AWS Services
- 172.A developer is building a serverless application where an AWS Lambda function processes data from an Amazon SQS queue. The data processing can sometimes fail due to transient issues or malformed messages. To prevent lost messages and allow for later inspection and reprocessing, which SQS feature should the developer configure?Development with AWS Services
- 173.A developer is using AWS CodeDeploy to deploy an application to a fleet of Amazon EC2 instances. Deployments often fail with a 'Script timed out' error during the `ApplicationStop` lifecycle event. The application takes a few minutes to gracefully shut down. The CodeDeploy agent logs on the EC2 instances show the `ApplicationStop` script starting but then abruptly terminating without completing. What is the MOST efficient way to resolve this issue?Troubleshooting and Monitoring
- 174.A developer is monitoring an application deployed on Amazon EC2 instances behind an Application Load Balancer (ALB). They observe an increasing number of HTTP 500 errors originating from the EC2 instances, as reported by the ALB's CloudWatch metrics. The EC2 instances show high CPU utilization and memory usage, but are not crashing. The application logs indicate frequent database connection timeouts. What action should the developer take FIRST to address these issues?Troubleshooting and Monitoring
- 175.A Lambda function processes messages from an SQS queue. Developers notice that sometimes messages are processed multiple times, even though the function successfully completes its execution. The Lambda function is configured with a concurrency limit of 10 and processes messages in batches of 1. What is the MOST likely cause of the duplicate processing?Troubleshooting and Monitoring
- 176.A developer is building a serverless application using AWS Lambda and Amazon SQS. They have configured a Lambda function to process messages from an SQS queue. Recently, they've observed that some messages are being processed multiple times, even though the Lambda function successfully processes them and returns without error. The SQS queue is standard, and the Lambda function has a batch size of 10. What is the MOST likely reason for the duplicate processing?Troubleshooting and Monitoring
- 177.A developer is observing high latency for an AWS Elastic Beanstalk application. The application logs show that requests are frequently waiting for available database connections. The database (Amazon RDS) metrics indicate high CPU utilization and a large number of active connections. Scaling up the Elastic Beanstalk environment's EC2 instances has not resolved the issue. What is the MOST effective immediate action to reduce application latency?Troubleshooting and Monitoring
- 178.A developer has deployed a new application on AWS using Amazon EC2 instances and an Application Load Balancer (ALB). Users are reporting intermittent 503 Service Unavailable errors. Upon investigation, the developer notices that the EC2 instances behind the ALB appear healthy. Which of the following is the MOST likely cause of the 503 errors?Troubleshooting and Monitoring
- 179.A developer is troubleshooting an AWS Lambda function that intermittently fails with a 'Task timed out' error, even though the function's configured timeout is 30 seconds. Upon inspecting CloudWatch Logs, they observe that the function often completes its core logic within 10-15 seconds but sometimes hangs for an extended period before the timeout. The Lambda function accesses resources within a VPC. What is the MOST likely cause of this intermittent timeout issue?Troubleshooting and Monitoring
- 180.A developer has implemented AWS CloudWatch alarms for an Amazon SQS queue. The alarms are configured to trigger when the 'ApproximateNumberOfMessagesVisible' metric exceeds 100 for 5 consecutive periods of 1 minute. However, during a recent incident, the queue backlog grew significantly (over 1000 messages), but the CloudWatch alarm did not trigger. Upon investigation, the developer found that the 'ApproximateNumberOfMessagesVisible' metric never consistently stayed above 100 for the full 5-minute period, even though the total messages in the queue were high. Which of the following is the MOST likely reason the alarm did not trigger?Troubleshooting and Monitoring
- 181.A developer is using AWS CodeDeploy to deploy an application to a fleet of Amazon EC2 instances. During a recent deployment, some instances failed with a 'ScriptTimedOut' error during the 'AfterInstall' hook, even though the script typically completes within 30 seconds. The CodeDeploy agent logs on the affected instances show that the script started successfully but then no further output was recorded until the timeout. The default timeout for CodeDeploy hooks is 3600 seconds (1 hour). What is the MOST likely cause of this 'ScriptTimedOut' error?Troubleshooting and Monitoring
- 182.A developer is using AWS Systems Manager Parameter Store to manage configuration values for an application. The application deployed on an EC2 instance attempts to retrieve a parameter but intermittently receives an `AccessDeniedException`. The EC2 instance's IAM role has `ssm:GetParameter` permission for the specific parameter ARN. What is the MOST likely reason for this intermittent error?Troubleshooting and Monitoring
- 183.A developer is building a serverless application using AWS Lambda and Amazon DynamoDB. The application experiences intermittent 'ProvisionedThroughputExceededException' errors when writing to a specific DynamoDB table, especially during peak traffic. The table is configured with on-demand capacity mode, and the Lambda function is retrying failed writes with exponential backoff. Which of the following is the MOST likely reason for these errors, given the on-demand capacity mode?Troubleshooting and Monitoring
- 184.A developer is investigating an issue where an AWS Fargate service running a Docker container intermittently stops and restarts. CloudWatch Container Insights metrics show that the 'MemoryUtilization' for the container frequently spikes close to 100% just before the restarts. The application logs within the container do not show any specific errors related to memory, only unexpected shutdowns. The Fargate task definition specifies a 'memory' value of 512MB and a 'memoryReservation' of 256MB. Which of the following is the MOST effective action to address the container restarts?Troubleshooting and Monitoring
- 185.A company uses AWS X-Ray to trace requests through a microservices architecture. A developer notices that while individual service calls are being traced, the end-to-end trace view often shows disconnected segments, or a new trace starts for subsequent service calls, rather than continuing the original trace. All services are instrumented with the X-Ray SDK. Which of the following is the MOST likely cause of this issue?Troubleshooting and Monitoring
- 186.A developer is using AWS Step Functions to orchestrate a complex workflow. They notice that one of the Lambda functions invoked by a state machine occasionally fails with a `Lambda.TooManyRequestsException` error. The Lambda function itself is not experiencing high concurrency when invoked directly, and its configured concurrency limit is sufficiently high. What is the MOST likely cause of this error within the Step Functions context?Troubleshooting and Monitoring
- 187.A developer has configured an Amazon Kinesis Data Stream with 5 shards. A Lambda function processes records from this stream. Recently, the developer noticed an increasing trend in the 'IteratorAgeMilliseconds' metric in CloudWatch for the Lambda function, sometimes exceeding the configured Lambda timeout. This indicates that the Lambda function is falling behind in processing records. Which of the following is the MOST effective action to improve the processing rate and reduce iterator age?Troubleshooting and Monitoring
- 188.A developer is observing high latency and occasional 5xx errors from an API Gateway endpoint that invokes a Lambda function. The Lambda function logs indicate successful execution within milliseconds, and CloudWatch metrics for Lambda show no errors or throttling. However, API Gateway metrics for the endpoint show a high 'IntegrationLatency' and '5XXError' rate. Which of the following is the MOST likely cause of the issue?Troubleshooting and Monitoring
- 189.A developer is using AWS CloudFormation to deploy an application. After a recent update to a stack, the deployment is stuck in an 'UPDATE_ROLLBACK_FAILED' state. Upon reviewing the CloudFormation events, they see an error indicating 'The following resource(s) failed to update: [MyEC2Instance]'. The EC2 instance itself appears to be running, but the stack remains stuck. What is the MOST appropriate next step to resolve this issue and re-enable stack operations?Troubleshooting and Monitoring
- 190.A developer has configured AWS CloudWatch Logs to export logs from a Lambda function to an Amazon S3 bucket. They notice that while the Lambda function is actively generating logs, new log files are not appearing in the S3 bucket as expected. They've verified the CloudWatch Logs subscription filter is active and correctly points to the S3 destination. What is the MOST likely cause of this issue?Troubleshooting and Monitoring
- 191.A developer is creating a new AWS Lambda function that needs to access a private Amazon RDS instance within a VPC. The Lambda function is currently failing to connect to the database, resulting in connection timeout errors. The EC2 security group attached to the RDS instance allows inbound traffic on port 5432 from the security group associated with the Lambda ENI. Which of the following is the MOST likely reason for the connection failure?Troubleshooting and Monitoring
- 192.A developer is troubleshooting an Amazon S3 event notification configured to invoke an AWS Lambda function. The Lambda function is not being invoked when new objects are uploaded to the S3 bucket, despite the objects appearing successfully in the bucket. Reviewing the S3 event configuration in the AWS Management Console shows that the notification is correctly pointing to the Lambda function. What is the MOST likely misconfiguration?Troubleshooting and Monitoring
- 193.A development team is using AWS CodeBuild for their continuous integration pipeline. Recently, they've noticed that builds are failing with 'OutOfMemoryError' during the 'install' phase, even though the source code repository hasn't changed. The build project is configured to use 'build.general1.small' compute type. Which action should the developer take to resolve this issue MOST efficiently?Troubleshooting and Monitoring
- 194.A developer has implemented a new feature in an application that involves uploading large files directly to an S3 bucket using presigned URLs. Users are reporting that uploads intermittently fail with a '403 Forbidden' error, even though the presigned URL was generated correctly with appropriate permissions. The application code generating the presigned URL does not specify any 'Content-Type' or 'Content-MD5' during generation, but the client-side upload includes a 'Content-Type' header. Which of the following is the MOST likely cause of the 403 Forbidden errors?Troubleshooting and Monitoring
- 195.A developer is investigating why an AWS CodeBuild project is failing consistently during the `BUILD` phase. The build logs show errors indicating `Cannot connect to Docker daemon` and `permission denied while trying to connect to the Docker daemon socket`. The CodeBuild project is configured with a Linux environment and uses a standard image. What is the MOST likely cause of this issue?Troubleshooting and Monitoring
- 196.A developer is troubleshooting an AWS Step Functions state machine that invokes a Lambda function. The state machine consistently fails at the Lambda invocation step with a 'Lambda.Unknown' error. The Lambda function itself, when invoked directly, executes successfully without any errors and returns the expected output. The Step Functions execution role has the necessary 'lambda:InvokeFunction' permission. What is the MOST likely cause of the 'Lambda.Unknown' error in Step Functions?Troubleshooting and Monitoring
- 197.A developer is deploying a new microservice to AWS Fargate. The microservice needs to store temporary, sensitive data in its ephemeral storage. The company's compliance requirements mandate that all data at rest, including ephemeral storage, must be encrypted using customer-managed keys (CMKs) from AWS Key Management Service (KMS). How can the developer ensure that the Fargate task's ephemeral storage is encrypted with a KMS CMK?Security
- 198.A developer is building a mobile application that needs to retrieve images stored in an Amazon S3 bucket. The images are private and should only be accessible for a limited time by authenticated users. The application should not expose AWS credentials directly to the client. How can the developer provide temporary, secure access to these S3 objects?Security
- 199.A developer is building a mobile application that needs to securely store user-specific data in an Amazon DynamoDB table. Each user should only be able to access and modify their own data, and no other user's data. The application uses Amazon Cognito for user authentication. How can the developer implement this fine-grained access control for DynamoDB?Security
- 200.A company is developing a new serverless application using AWS Lambda functions. This application needs to access a relational database hosted on Amazon RDS. The database credentials (username and password) must be stored securely and rotated automatically without requiring changes to the Lambda function code. The development team wants to retrieve these credentials at runtime. Which AWS service should they use?Security