Step2Study
IT & TechnologyDVA-C02100% Free

AWS Certified Developer – Associate (DVA-C02)

Practice bank
208 Qs
Real exam
65 Qs
Time limit
130 min
Passing
The AWS Certified Developer – Associate exam is a pass or fail exam. The examination uses a compensatory scoring model, which means that your overall score determines your pass/fail status. Each section of the exam has a target minimum score. The exam does not publish a passing score.

Exam blueprint

Development with AWS Services
32%
Security
26%
Deployment
24%
Troubleshooting and Monitoring
18%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 180 min · pass 72% · 208 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

AWS Certified Developer – Associate (DVA-C02) practice test questions

Sample questions from the 208-question bank, with answers and explanations.

All questions
  1. 1. A developer is configuring an AWS CodeBuild project for a large application that has many dependencies. The build process frequently downloads the same dependencies from external repositories, leading to long build times. The developer wants to optimize build times by reusing previously downloaded dependencies. Which CodeBuild feature should be used to achieve this efficiently?

    Deployment

    • A. Use a custom Docker image for CodeBuild with pre-installed dependencies.
    • B. Increase the compute capacity of the CodeBuild project.
    • C. Configure CodeBuild caching to an Amazon S3 bucket.
    • D. Implement a custom script in the buildspec.yml to download dependencies only if they are missing.
    Show answer

    C. Configure CodeBuild caching to an Amazon S3 bucket.

    CodeBuild caching to an Amazon S3 bucket is the most effective and managed solution for reusing dependencies. It allows CodeBuild to store and retrieve build artifacts and dependencies, significantly reducing build times for subsequent builds by avoiding redundant downloads.

  2. 2. A developer is configuring an AWS CodePipeline to deploy a serverless application consisting of AWS Lambda functions, Amazon API Gateway, and Amazon DynamoDB tables. The pipeline needs to automatically create and manage these resources. Which type of deployment action should be used in the deployment stage of the CodePipeline?

    Deployment

    • A. Amazon S3 deployment
    • B. AWS CodeDeploy deployment
    • C. AWS CloudFormation stack update
    • D. AWS Elastic Beanstalk deployment
    Show answer

    C. AWS CloudFormation stack update

    For serverless applications defined using Infrastructure as Code (like AWS SAM or raw CloudFormation), the deployment involves creating or updating a CloudFormation stack. CodePipeline's CloudFormation action type is specifically designed to manage these stack operations, ensuring all resources are provisioned and updated consistently.

  3. 3. A company uses AWS CodeCommit for their source code repository and AWS CodePipeline to automate their CI/CD process. They need to ensure that every code change pushed to a specific branch in CodeCommit automatically triggers a new pipeline execution. What is the most efficient way to configure this integration?

    Deployment

    • A. Manually start the CodePipeline after every push to CodeCommit.
    • B. Use a Lambda function triggered by CodeCommit notifications to start the CodePipeline.
    • C. Configure the CodePipeline's source stage to use an AWS CodeCommit repository with event-based change detection.
    • D. Set up a CloudWatch Event Rule to detect CodeCommit push events and trigger the CodePipeline.
    Show answer

    C. Configure the CodePipeline's source stage to use an AWS CodeCommit repository with event-based change detection.

    CodePipeline's source stage has direct integration with CodeCommit. By selecting CodeCommit as the source provider and enabling 'Start the pipeline on source code change', CodePipeline will automatically detect new pushes to the configured branch and initiate a new pipeline execution, making it the most efficient and native solution.

  4. 4. A development team is deploying a new version of a critical web application to Amazon EC2 instances using AWS CodeDeploy. They need to ensure that the application is fully functional and responsive before any traffic is routed to the newly deployed instances. If the application does not pass these health checks, the deployment should automatically roll back. Which CodeDeploy lifecycle event hook and associated action should be used to achieve this?

    Deployment

    • A. AfterAllowTraffic hook to perform post-deployment monitoring.
    • B. BeforeInstall hook to run basic unit tests.
    • C. ValidateService hook to run comprehensive health checks and trigger rollback on failure.
    • D. ApplicationStart hook to start the application service.
    Show answer

    C. ValidateService hook to run comprehensive health checks and trigger rollback on failure.

    The ValidateService lifecycle event hook is specifically designed for running comprehensive health checks and validation tests after the application has started on the new deployment, but before any traffic is directed to it. If the scripts executed during this hook fail, CodeDeploy can be configured to automatically roll back the deployment, ensuring that only healthy instances receive traffic.

  5. 5. A developer is configuring an AWS CodePipeline to deploy a web application to Amazon S3 and Amazon CloudFront. After the new version of the application is uploaded to S3, the CloudFront distribution needs to be invalidated to ensure users receive the latest content. Which action type should be used in CodePipeline to automate this CloudFront invalidation?

    Deployment

    • A. Amazon S3 deploy action
    • B. AWS CloudFormation deploy action
    • C. AWS Lambda invoke action
    • D. AWS CodeBuild action
    Show answer

    D. AWS CodeBuild action

    AWS CodeBuild can be used to run custom commands, including AWS CLI commands. A CodeBuild action in CodePipeline can execute the `aws cloudfront create-invalidation` command to invalidate the CloudFront distribution after new content is deployed to S3.

  6. 6. A developer needs to deploy a new feature to an existing application running on Amazon EC2 instances managed by an Auto Scaling Group. The deployment must ensure zero downtime and provide an easy rollback mechanism if issues are detected. The new feature requires a database schema change that must be applied before the new application version receives traffic. Which AWS CodeDeploy deployment type and configuration would best meet these requirements?

    Deployment

    • A. In-place deployment with a `BeforeInstall` hook for schema changes.
    • B. All-at-once deployment with a `ApplicationStop` hook for schema changes.
    • C. Linear deployment with a Lambda function to apply schema changes between increments.
    • D. Blue/Green deployment with a `BeforeAllowTraffic` hook for schema changes.
    Show answer

    D. Blue/Green deployment with a `BeforeAllowTraffic` hook for schema changes.

    Blue/Green deployment in CodeDeploy creates a completely new set of instances (green environment), deploys the new application, and allows for pre-traffic hooks (`BeforeAllowTraffic`) to run database schema changes on the new environment before traffic is cut over. This ensures zero downtime and provides an automatic rollback to the old (blue) environment if issues arise during or after the traffic shift.

  7. 7. A company is using AWS CodePipeline to deploy a serverless application consisting of AWS Lambda functions. They want to implement a deployment strategy that gradually shifts traffic to the new Lambda function version and automatically rolls back if errors are detected. They also need to ensure that the new version is tested with a small percentage of production traffic before full cutover. Which deployment type in CodeDeploy for Lambda should they configure?

    Deployment

    • A. Linear
    • B. Canary
    • C. AllAtOnce
    • D. Blue/Green
    Show answer

    B. Canary

    The requirements of gradually shifting traffic, monitoring for errors, automatic rollback, and testing with a small percentage of production traffic are all hallmarks of a Canary deployment strategy. CodeDeploy supports Canary deployments for Lambda functions.

  8. 8. A developer needs to deploy a new version of a serverless application consisting of AWS Lambda functions and Amazon API Gateway endpoints. The deployment strategy requires routing a small percentage of production traffic to the new Lambda function version for a short period to monitor for errors before shifting 100% of the traffic. Which AWS CodeDeploy deployment configuration should be used for this scenario?

    Deployment

    • A. CodeDeployDefault.LambdaLinear10PercentEvery1Minute
    • B. CodeDeployDefault.LambdaCanary10Percent5Minutes
    • C. CodeDeployDefault.LambdaAllAtOnce
    • D. CodeDeployDefault.LambdaBlueGreen
    Show answer

    B. CodeDeployDefault.LambdaCanary10Percent5Minutes

    The CodeDeployDefault.LambdaCanary10Percent5Minutes configuration shifts 10% of traffic to the new Lambda function version for 5 minutes, then shifts the remaining 90%. This aligns with the requirement to route a small percentage of traffic for monitoring before a full shift.

  9. 9. A developer is deploying an application to Amazon EC2 instances using AWS CodeDeploy. They need to execute a custom script on each instance immediately after the new application revision files have been copied to the instance, but before the application's dependencies are installed or the application starts. Which CodeDeploy lifecycle event hook should they use in their `appspec.yml` file?

    Deployment

    • A. AfterInstall
    • B. ValidateService
    • C. BeforeInstall
    • D. ApplicationStart
    Show answer

    C. BeforeInstall

    The `BeforeInstall` lifecycle event hook in CodeDeploy runs after the application revision files are downloaded to the instance but before any installation or dependency resolution processes begin. This makes it the ideal place to execute a custom script that needs to run on the raw copied files before they are 'installed' or the application starts.

  10. 10. A development team uses AWS CodeCommit for their source code repository and AWS CodePipeline for CI/CD. They want to ensure that every pull request (PR) merge to the `main` branch automatically triggers a build and a suite of unit tests before the code is deployed. How can they configure CodePipeline to achieve this?

    Deployment

    • A. Integrate AWS CodeCommit with AWS CodePipeline, configuring the source stage to use the `main` branch as a trigger.
    • B. Set up an AWS CodeBuild project to poll the `main` branch for changes.
    • C. Use an AWS Lambda function to monitor CodeCommit PR events and manually trigger CodePipeline.
    • D. Configure the CodePipeline to trigger on commits to the `main` branch.
    Show answer

    A. Integrate AWS CodeCommit with AWS CodePipeline, configuring the source stage to use the `main` branch as a trigger.

    AWS CodePipeline natively integrates with AWS CodeCommit. By configuring the CodePipeline source stage to point to the `main` branch of the CodeCommit repository, CodePipeline will automatically detect new commits (including those from merged pull requests) and trigger the pipeline, initiating the build and test stages.

  11. 11. A developer needs to deploy an AWS Lambda function that processes sensitive customer data. To meet compliance requirements, the Lambda function must only be able to access specific Amazon S3 buckets and a particular Amazon DynamoDB table. Additionally, the function should not have public internet access. How should the developer configure the Lambda function and its permissions?

    Deployment

    • A. Deploy the Lambda function inside a VPC, configure VPC endpoints for S3 and DynamoDB, and attach an IAM policy with least privilege access to the specific resources.
    • B. Deploy the Lambda function inside a VPC, configure a NAT Gateway for S3 and DynamoDB access, and attach an IAM policy with least privilege access.
    • C. Attach an IAM policy to the Lambda function's execution role with full S3 and DynamoDB access, and ensure no security groups are attached to the function.
    • D. Attach an IAM policy to the Lambda function's execution role allowing access to all S3 buckets and DynamoDB, and configure a NAT Gateway for internet access.
    Show answer

    A. Deploy the Lambda function inside a VPC, configure VPC endpoints for S3 and DynamoDB, and attach an IAM policy with least privilege access to the specific resources.

    To restrict network access and enforce least privilege, the Lambda function should be deployed within a VPC. To allow access to S3 and DynamoDB without traversing the public internet, VPC endpoints (Gateway Endpoint for S3, Interface Endpoint for DynamoDB) are necessary. Finally, an IAM policy must be attached to the Lambda's execution role, granting only the required permissions to the specific S3 buckets and DynamoDB table.

  12. 12. A company uses AWS CodePipeline to deploy its microservices to Amazon ECS. Each microservice has its own pipeline. They want to ensure that the latest approved Docker image from an Amazon ECR repository is used in the ECS task definition during deployment, without hardcoding image tags in the source code or build process. How can this be achieved reliably?

    Deployment

    • A. Manually update the ECS task definition with the correct image tag before each deployment.
    • B. Store the image tag in AWS Systems Manager Parameter Store and retrieve it in the CodeDeploy AppSpec.
    • C. Configure the CodePipeline source stage to pull the ECS task definition from a Git repository with a placeholder tag.
    • D. Use the output artifact from a CodeBuild stage (which builds and pushes the image) as input to a subsequent ECS deployment action, dynamically replacing the image tag in the task definition.
    Show answer

    D. Use the output artifact from a CodeBuild stage (which builds and pushes the image) as input to a subsequent ECS deployment action, dynamically replacing the image tag in the task definition.

    CodeBuild can output a JSON file containing the ECR image URI and tag after building and pushing a Docker image. This output artifact can then be used as input to an ECS deployment action. The ECS deployment action in CodePipeline has a feature to dynamically replace the image tag within an ECS task definition file using values from the input artifact, ensuring the latest image is always used.

  13. 13. A developer needs to deploy an AWS Lambda function that processes sensitive customer data. The function needs to connect to an Amazon RDS database instance located in a private subnet within a VPC. Additionally, the Lambda function should only access specific AWS services (e.g., S3, DynamoDB) via private endpoints, without routing traffic through the public internet. How should the Lambda function be configured?

    Deployment

    • A. Use a Lambda@Edge function and configure its permissions to access RDS and other AWS services directly.
    • B. Configure the Lambda function to run inside the VPC, assign it to a private subnet, and create VPC interface endpoints for S3 and DynamoDB.
    • C. Deploy the Lambda function outside the VPC and configure security groups to allow outbound access to RDS and public endpoints for S3/DynamoDB.
    • D. Place the Lambda function in a public subnet within the VPC and configure a NAT Gateway for outbound access to RDS and other AWS services.
    Show answer

    B. Configure the Lambda function to run inside the VPC, assign it to a private subnet, and create VPC interface endpoints for S3 and DynamoDB.

    To connect to RDS in a private subnet and access other AWS services privately, the Lambda function must be configured to run within the VPC in a private subnet. VPC interface endpoints for S3 and DynamoDB ensure that traffic to these services remains within the AWS network, enhancing security and reducing latency.

  14. 14. A developer is configuring an AWS CodeBuild project to build a containerized application. The build process requires pulling a base image from a private Amazon ECR repository and then pushing the final built image to another ECR repository. What IAM permissions are essential for the CodeBuild service role to successfully perform these actions?

    Deployment

    • A. codebuild:StartBuild, codebuild:StopBuild, codebuild:BatchGetBuilds
    • B. s3:GetObject, s3:PutObject, s3:ListBucket
    • C. ecr:GetDownloadUrlForLayer, ecr:BatchGetImage, ecr:BatchCheckLayerAvailability, ecr:InitiateLayerUpload, ecr:UploadLayerPart, ecr:CompleteLayerUpload, ecr:PutImage
    • D. ecr:DescribeRepositories, ecr:ListImages, ecr:GetAuthorizationToken
    Show answer

    C. ecr:GetDownloadUrlForLayer, ecr:BatchGetImage, ecr:BatchCheckLayerAvailability, ecr:InitiateLayerUpload, ecr:UploadLayerPart, ecr:CompleteLayerUpload, ecr:PutImage

    To pull images, CodeBuild needs `GetDownloadUrlForLayer`, `BatchGetImage`, and `BatchCheckLayerAvailability`. To push images, it needs `InitiateLayerUpload`, `UploadLayerPart`, `CompleteLayerUpload`, and `PutImage`. These permissions cover the full lifecycle of pulling and pushing Docker images to and from ECR.

  15. 15. A developer is configuring an AWS CodeBuild project for a large application. The build process involves downloading many external dependencies that rarely change, which significantly increases build times. The team wants to optimize build performance by caching these dependencies. The CodeBuild project is used by multiple pipelines, and the cache needs to be persistent and accessible across different build runs and projects. Which caching mechanism should be implemented?

    Deployment

    • A. Docker layer caching within the build environment.
    • B. Local caching using CodeBuild's local cache.
    • C. AWS Systems Manager Parameter Store to store dependency paths.
    • D. Amazon S3 caching using a dedicated S3 bucket.
    Show answer

    D. Amazon S3 caching using a dedicated S3 bucket.

    Amazon S3 caching is the recommended approach for persistent caching across multiple CodeBuild projects and build runs. It allows CodeBuild to store and retrieve dependencies in an S3 bucket, making them available for subsequent builds, significantly reducing download times for unchanging dependencies. Local caching is instance-specific and non-persistent, while Docker layer caching is for Docker images, not general dependencies.

  16. 16. A developer is building a serverless application using AWS Lambda and Amazon API Gateway. They need to ensure that different versions of their Lambda function can be invoked through the same API Gateway endpoint, allowing for controlled traffic shifting between versions. Which Lambda feature, when combined with API Gateway stages, enables this functionality?

    Deployment

    • A. Lambda aliases
    • B. Lambda environment variables
    • C. Lambda layers
    • D. Lambda provisioned concurrency
    Show answer

    A. Lambda aliases

    Lambda aliases are pointers to specific Lambda function versions. When integrated with API Gateway stages, aliases allow you to map an API Gateway stage (e.g., 'prod' or 'beta') to a specific Lambda alias, which in turn can be configured to split traffic between two Lambda function versions, enabling canary deployments or A/B testing.

  17. 17. A company is performing a blue/green deployment of a new application version to an Amazon ECS service using AWS CodeDeploy. They want to shift traffic to the new task set in stages: 10% for 5 minutes, then 50% for 10 minutes, and finally 100%. During these stages, they need to run automated integration tests to ensure the new version is healthy before proceeding to the next traffic shift. How can this be effectively configured?

    Deployment

    • A. Configure a CodeDeploy Canary deployment strategy with a single AfterAllowTraffic hook.
    • B. Define a custom CodeDeploy Linear deployment strategy with multiple traffic shift steps and integrate Lambda functions as hooks (e.g., AfterAllowTraffic) to run tests after each shift.
    • C. Implement a CodeDeploy AllAtOnce deployment and manually shift traffic using an Application Load Balancer.
    • D. Use a CodeDeploy Linear deployment strategy with a single PreTraffic hook to run all tests.
    Show answer

    B. Define a custom CodeDeploy Linear deployment strategy with multiple traffic shift steps and integrate Lambda functions as hooks (e.g., AfterAllowTraffic) to run tests after each shift.

    CodeDeploy's Linear deployment strategies allow for traffic to be shifted in specified percentages over defined intervals. By defining a custom Linear strategy with multiple steps (e.g., 10%, 50%, 100%), and integrating Lambda functions as AfterAllowTraffic hooks, automated tests can be executed after each incremental traffic shift. This approach ensures the new version is validated at each stage before full traffic cutover.

  18. 18. A company is using AWS CodePipeline to automate the deployment of a containerized application to Amazon ECS. They need to ensure that database schema migrations are executed successfully before the new application containers are brought online, and that a rollback mechanism is in place if the migrations fail. Which CodePipeline action type and integration would best support this requirement?

    Deployment

    • A. Implement a Lambda function within the CodePipeline to trigger schema migrations, followed by an ECS update service action.
    • B. Utilize a CodeDeploy action with a Blue/Green deployment strategy for ECS, configuring a pre-traffic hook for schema migrations.
    • C. Add a CodeBuild action to run schema migrations before the ECS deployment, with a manual approval step.
    • D. Add an SQS queue to trigger an EC2 instance to perform schema migrations, then update the ECS service through CodePipeline.
    Show answer

    B. Utilize a CodeDeploy action with a Blue/Green deployment strategy for ECS, configuring a pre-traffic hook for schema migrations.

    AWS CodeDeploy with a Blue/Green deployment strategy for Amazon ECS is specifically designed to handle this scenario. The pre-traffic hook allows custom scripts (like database schema migrations) to run on the new task set before traffic is shifted. If the hook fails or an alarm is triggered, CodeDeploy can automatically roll back to the old task set, ensuring data integrity and application availability.

  19. 19. A developer is configuring an AWS CodeBuild project that needs to fetch sensitive configuration parameters, such as API keys and database credentials, during the build process. These parameters are stored securely in AWS Systems Manager Parameter Store. How should the developer configure CodeBuild to access these parameters securely?

    Deployment

    • A. Store the parameters in an S3 bucket and use the `aws s3 cp` command in `buildspec.yml` to retrieve them.
    • B. Reference the Parameter Store parameters in the `buildspec.yml` file using the `parameter-store` syntax, ensuring the CodeBuild service role has `ssm:GetParameters` permissions.
    • C. Pass the parameters as environment variables directly in the CodeBuild project settings.
    • D. Hardcode the parameters directly into the `buildspec.yml` file.
    Show answer

    B. Reference the Parameter Store parameters in the `buildspec.yml` file using the `parameter-store` syntax, ensuring the CodeBuild service role has `ssm:GetParameters` permissions.

    AWS CodeBuild natively integrates with AWS Systems Manager Parameter Store. By referencing parameters using the `parameter-store` syntax in the `buildspec.yml` file, CodeBuild can securely fetch these values at build time. It's crucial that the CodeBuild service role has `ssm:GetParameters` permissions to access the specified parameters.

  20. 20. A company is experiencing slow build times in their AWS CodeBuild projects. They have identified that downloading dependencies and Docker images takes a significant portion of the build duration. The builds are frequently run on the same or similar codebases. What is the most effective way to reduce build times in this scenario?

    Deployment

    • A. Enable caching for the CodeBuild project.
    • B. Use a smaller base Docker image for the build environment.
    • C. Increase the compute type of the CodeBuild project.
    • D. Split the monolithic buildspec.yml into multiple smaller buildspecs.
    Show answer

    A. Enable caching for the CodeBuild project.

    Enabling caching for CodeBuild projects allows frequently accessed dependencies and Docker layers to be stored and reused across builds. This significantly reduces download times for subsequent builds, directly addressing the identified bottleneck.

  21. 21. A development team uses AWS CodeBuild for continuous integration. They need to ensure that specific sensitive environment variables, such as API keys, are available during the build process but are not exposed in plain text in the build logs or source code. How should these variables be securely managed and injected into the CodeBuild environment?

    Deployment

    • A. Define them directly in the buildspec.yml file as plaintext environment variables.
    • B. Store them in AWS Systems Manager Parameter Store and reference them in the buildspec.yml.
    • C. Hardcode them as constants in the application's source code.
    • D. Pass them as command-line arguments to the CodeBuild project.
    Show answer

    B. Store them in AWS Systems Manager Parameter Store and reference them in the buildspec.yml.

    AWS Systems Manager Parameter Store allows storing sensitive data securely. CodeBuild can then retrieve these parameters at build time by referencing them in the buildspec.yml file, ensuring they are not exposed in logs or source code.

  22. 22. A company is using AWS CodePipeline to automate its software release process. They have a stage that deploys an application to Amazon EC2 instances using AWS CodeDeploy. After deployment, they need to run a series of integration tests. Where should the commands for these integration tests be specified within the CodeDeploy deployment lifecycle?

    Deployment

    • A. AfterAllowTraffic hook in the AppSpec file
    • B. ApplicationStop hook in the AppSpec file
    • C. ValidateService hook in the AppSpec file
    • D. BeforeInstall hook in the AppSpec file
    Show answer

    C. ValidateService hook in the AppSpec file

    The ValidateService hook is specifically designed for running tests and validating the health of the newly deployed application after it has started and is serving traffic. This is the ideal place for integration tests.

  23. 23. A company is planning to migrate an on-premises application to AWS. The application consists of several web servers and a database. They want to use AWS CodeDeploy for automated deployments to Amazon EC2 instances. To prepare the on-premises servers for CodeDeploy, they need to install and configure an agent. Which agent needs to be installed on the on-premises servers to enable CodeDeploy deployments?

    Deployment

    • A. AWS CodeDeploy Agent
    • B. AWS Systems Manager Agent (SSM Agent)
    • C. AWS CLI
    • D. AWS CloudWatch Agent
    Show answer

    A. AWS CodeDeploy Agent

    To enable AWS CodeDeploy to deploy applications to Amazon EC2 instances or on-premises servers, the AWS CodeDeploy agent must be installed on those target instances. This agent is responsible for downloading application revisions, running deployment scripts, and reporting deployment status back to CodeDeploy.

  24. 24. A software company is developing a new serverless application that utilizes AWS Lambda functions. They want to ensure that all Lambda function code is packaged and deployed consistently across different environments (development, staging, production) using Infrastructure as Code. Which AWS service is best suited for defining and deploying these serverless resources?

    Deployment

    • A. AWS Serverless Application Model (SAM)
    • B. AWS Elastic Beanstalk
    • C. AWS Cloud9
    • D. AWS CodeDeploy
    Show answer

    A. AWS Serverless Application Model (SAM)

    AWS Serverless Application Model (SAM) is an open-source framework specifically designed for building serverless applications on AWS. It extends AWS CloudFormation, providing a simplified syntax for defining serverless resources like Lambda functions, API Gateway, and DynamoDB tables, and supports consistent deployment across environments.

  25. 25. A company is deploying a new version of their web application to an Auto Scaling group of EC2 instances using AWS CodeDeploy. They want to ensure that the new version is thoroughly tested before it fully replaces the old version, allowing for a gradual rollout and easy rollback if issues are detected. Which CodeDeploy deployment type best fits these requirements?

    Deployment

    • A. In-place deployment
    • B. Blue/green deployment
    • C. Rolling update deployment
    • D. All-at-once deployment
    Show answer

    B. Blue/green deployment

    Blue/green deployment is ideal for scenarios requiring extensive testing and easy rollback. It deploys the new version to a separate set of instances (green environment) while the old version (blue environment) remains active. Once verified, traffic is shifted, and the old environment can be terminated or kept for rollback.

AWS Certified Developer – Associate (DVA-C02) flashcards

Tap a card to flip it. 135 flashcards in the full deck.

  • CodeBuild S3 Caching

    Flip card

    AWS CodeBuild can use an Amazon S3 bucket to cache build artifacts and dependencies, significantly reducing build times by reusing data from previous builds.

    • Reduces build times by avoiding redundant downloads.
    • Supports various caching modes (full, custom).
    • Uses S3 for durable and scalable cache storage.
    Study this card →
  • CodePipeline CloudFormation Action

    Flip card

    An action type in AWS CodePipeline used to create, update, or delete AWS CloudFormation stacks, managing the deployment of infrastructure as code.

    • Manages CloudFormation stack lifecycle.
    • Ideal for deploying serverless applications (SAM templates).
    • Ensures consistent resource provisioning.
    Study this card →
  • CodeCommit CodePipeline Integration

    Flip card

    AWS CodePipeline natively integrates with AWS CodeCommit, allowing automatic pipeline execution triggers upon code changes (e.g., pushes to a branch) in the CodeCommit repository.

    • CodeCommit as a direct source provider in CodePipeline.
    • Automatic pipeline starts on code changes.
    • Simplifies CI/CD automation for CodeCommit users.
    Study this card →
  • CodeDeploy ValidateService Hook

    Flip card

    A CodeDeploy lifecycle event hook that executes scripts to perform health checks and validation tests on a newly deployed application *before* it starts receiving production traffic. Failures can trigger automatic rollbacks.

    • Runs after application starts, before traffic shift.
    • Ideal for comprehensive health and integration tests.
    • Failure can initiate automatic rollback.
    Study this card →
  • CodePipeline CloudFront Invalidation

    Flip card

    To ensure users receive the latest content after deploying to S3 via CodePipeline, a CloudFront distribution's cache must be invalidated. This is typically automated using an AWS CodeBuild action within CodePipeline to execute the `aws cloudfront create-invalidation` CLI command.

    • Required for fresh content delivery.
    • Automated using CodeBuild action.
    • Executes `aws cloudfront create-invalidation`.
    Study this card →
  • CodeDeploy Blue/Green with Pre-Traffic Hooks

    Flip card

    A CodeDeploy strategy for EC2/Auto Scaling Groups that creates a new environment, deploys the application, and uses pre-traffic hooks (like `BeforeAllowTraffic`) to run tasks like database migrations on the new environment before traffic is shifted, ensuring zero-downtime and easy rollback.

    • Zero-downtime deployments.
    • New environment created (green).
    • Pre-traffic hooks for migrations.
    Study this card →
  • CodeDeploy Lambda Canary Deployment

    Flip card

    AWS CodeDeploy can manage Lambda deployments using a Canary strategy, where a new function version receives a small percentage of traffic, is monitored, and then gradually rolled out (or rolled back) based on predefined alarms. This minimizes risk during serverless updates.

    • Gradual traffic shift for Lambda.
    • Monitors for errors using CloudWatch alarms.
    • Automated rollback on alarm trigger.
    Study this card →
  • CodeDeploy Lambda Canary

    Flip card

    A CodeDeploy deployment type for Lambda functions that allows a new version to receive a small percentage of production traffic for a specified duration before shifting all traffic, enabling real-time monitoring.

    • Uses Lambda traffic shifting.
    • Routes a small percentage first.
    • Monitors for errors before full rollout.
    Study this card →
  • CodeDeploy BeforeInstall Hook

    Flip card

    An AWS CodeDeploy lifecycle event hook that executes scripts after the application revision files are downloaded to an instance, but before any installation or dependency resolution begins, allowing for pre-installation setup tasks.

    • Runs after file copy.
    • Runs before installation/dependencies.
    • Useful for pre-setup tasks.
    Study this card →
  • Lambda VPC & Endpoints

    Flip card

    Deploying a Lambda function in a VPC provides network isolation. VPC endpoints allow private and secure access to AWS services like S3 and DynamoDB from within the VPC without routing through the public internet.

    • Lambda in VPC isolates network traffic.
    • VPC endpoints provide private access to AWS services.
    • Gateway Endpoint for S3, Interface Endpoint for DynamoDB.
    Study this card →
  • CodePipeline ECS Image Update

    Flip card

    CodePipeline can dynamically update an Amazon ECS task definition's Docker image tag by consuming an 'imagedefinitions.json' artifact generated by a preceding CodeBuild stage.

    • CodeBuild generates 'imagedefinitions.json'.
    • This JSON contains ECR image URI and tag.
    • ECS deployment action uses this artifact to update task definition.
    Study this card →
  • CodeBuild ECR Permissions

    Flip card

    The specific IAM permissions required by the AWS CodeBuild service role to pull Docker images from and push Docker images to Amazon Elastic Container Registry (ECR).

    • Pulling requires layer/image retrieval.
    • Pushing requires layer upload/image put.
    • Permissions must be granted to CodeBuild's service role.
    Study this card →
  • Lambda Aliases & API Gateway Stages

    Flip card

    Lambda aliases point to specific Lambda function versions, and when integrated with API Gateway stages, they enable controlled traffic shifting and phased deployments by mapping stages to aliases.

    • Alias points to a version.
    • API Gateway stage maps to an alias.
    • Enables traffic shifting between versions.
    Study this card →
  • CodeDeploy Custom Linear Deployments with Hooks

    Flip card

    A CodeDeploy feature for ECS blue/green deployments that allows defining custom traffic shifting percentages and intervals, combined with lifecycle hooks (e.g., AfterAllowTraffic Lambda functions) to run validation tests after each staged traffic shift.

    • Customizable traffic shifting percentages and intervals.
    • Uses Lambda hooks for validation after each shift.
    • Ensures gradual rollout and validation at each stage.
    Study this card →
  • CodeDeploy Blue/Green for ECS

    Flip card

    A CodeDeploy deployment strategy for Amazon ECS that creates a new, identical environment (green task set), shifts traffic to it, and provides pre-traffic hooks for validation and automatic rollback capabilities.

    • Zero-downtime deployments for ECS.
    • Pre-traffic hooks for validation/migrations.
    • Automatic rollback on failure.
    Study this card →
  • CodeBuild Parameter Store Integration

    Flip card

    AWS CodeBuild's native capability to securely retrieve sensitive configuration parameters from AWS Systems Manager Parameter Store during the build process, preventing hardcoding or exposure.

    • Uses `parameter-store` syntax in `buildspec.yml`.
    • Requires `ssm:GetParameters` permission.
    • Securely injects parameters at build time.
    Study this card →
  • CodeBuild Caching

    Flip card

    AWS CodeBuild offers caching mechanisms to reduce build times by storing frequently used dependencies, Docker layers, and artifacts. This prevents repetitive downloads in subsequent builds, especially beneficial for projects with stable dependencies.

    • Reduces build duration.
    • Caches dependencies and Docker layers.
    • Supports S3, local, or custom caching.
    Study this card →
  • CodeDeploy AppSpec Hooks

    Flip card

    AppSpec file hooks define scripts to run at various stages of the CodeDeploy deployment lifecycle on an EC2/on-premises instance. These hooks allow for custom actions like installing dependencies, starting services, and running tests.

    • Defines deployment actions.
    • Specific hooks for different lifecycle events.
    • Scripts are executed on target instances.
    Study this card →
  • CodeDeploy Agent

    Flip card

    A software package that runs on target instances (EC2 or on-premises) and is responsible for managing deployments orchestrated by AWS CodeDeploy.

    • Required for CodeDeploy deployments to EC2/on-premises.
    • Downloads application revisions from S3/GitHub.
    • Executes scripts defined in the AppSpec file.
    Study this card →
  • AWS Serverless Application Model (SAM)

    Flip card

    An open-source framework for building serverless applications on AWS, using a simplified syntax to define resources like Lambda functions, API Gateway, and DynamoDB.

    • Extension of AWS CloudFormation.
    • Simplifies serverless resource definition.
    • Supports consistent deployment across environments.
    Study this card →
  • CodeDeploy Blue/Green Deployment

    Flip card

    A CodeDeploy strategy where a new version of an application is deployed to a completely separate environment (green) while the old version (blue) remains active. Traffic is then shifted to the new environment after validation.

    • Minimizes downtime during deployment.
    • Enables easy rollback to the previous version.
    • Allows thorough testing of the new version in a production-like environment before traffic shift.
    Study this card →
  • AWS Secrets Manager

    Flip card

    A service that helps you protect access to your applications, services, and IT resources. It enables you to easily rotate, manage, and retrieve database credentials, API keys, and other secrets throughout their lifecycle.

    • Securely stores and retrieves secrets.
    • Automates rotation of database credentials.
    • Integrates with RDS, Redshift, DocumentDB.
    Study this card →
  • CodeDeploy AfterInstall Hook

    Flip card

    A CodeDeploy lifecycle event hook that executes custom scripts immediately after the application revision files are copied to the instance.

    • Runs after application files are installed.
    • Runs before the application starts or traffic shifts.
    • Ideal for post-installation configuration or setup tasks.
    Study this card →
  • CodeBuild for Integration Tests

    Flip card

    Using AWS CodeBuild within an AWS CodePipeline to execute automated integration tests (e.g., API tests) as a dedicated stage, ensuring deployed components function correctly before proceeding.

    • Executes custom test scripts.
    • Uses `buildspec.yml` for commands.
    • Integrates seamlessly into CodePipeline.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.