CertSafari

    Free AWS Certified Developer - Associate (DVA-C02) Sample Questions

    35 free sample questions from our bank of 364+, covering every exam domain, with answers and detailed explanations. Updated September 2026.

    Domain 1: Development with AWS Services

    Subdomain 1.3: Use data stores in application development

    1.Which two statements about how DynamoDB stores and encrypts data at rest are correct? (Select TWO.)(Select 2)

    1. A.DynamoDB encrypts all table data at rest by default using an AWS-owned key at no additional cost, and this can optionally be changed to an AWS managed or customer managed KMS key
    2. B.DynamoDB does not encrypt data at rest by default; a developer must explicitly enable server-side encryption before creating the table or the data remains in plaintext
    3. C.DynamoDB only encrypts data at rest for tables using provisioned capacity mode, while every on-demand table stores its attribute values unencrypted
    4. D.DynamoDB requires a customer managed KMS key to be specified at table creation, and there is no default AWS-owned key option available for any table
    5. E.When a customer managed KMS key replaces the default AWS-owned key, no application code changes are needed, since DynamoDB transparently decrypts data on access
    Show answer & explanation

    Correct answers: A, E — DynamoDB encrypts all table data at rest by default using an AWS-owned key at no additional cost, and this can optionally be changed to an AWS managed or customer managed KMS key; When a customer managed KMS key replaces the default AWS-owned key, no application code changes are needed, since DynamoDB transparently decrypts data on access

    • A. AWS documentation states that DynamoDB encrypts all customer data at rest by default using an AWS-owned key with no additional charge, and developers can optionally switch to an AWS managed key or a customer managed key for more control.
    • B. Encryption at rest is not an opt-in feature that must be explicitly enabled; every DynamoDB table has encryption at rest applied automatically from creation, regardless of whether the developer configures anything.
    • C. Encryption at rest applies uniformly to DynamoDB tables regardless of capacity mode; there is no distinction between provisioned and on-demand tables in whether data is encrypted at rest.
    • D. A customer managed key is an optional choice for organizations that need full control over key policies and rotation; it is not required, since every table already defaults to encryption with an AWS-owned key.
    • E. Switching the encryption key type is a table-level configuration change; DynamoDB continues to transparently encrypt and decrypt data regardless of which key type is used, so no application code changes are required.

    Subdomain 1.3: Use data stores in application development

    2.A developer profiling a DynamoDB-backed API notices that queries filtering on a non-key attribute called `orderStatus` are slow and expensive at scale, even though the table already has a GSI on `customerId`. The team wants queries filtering by `orderStatus` and sorted by `orderDate` to be fast. Which two actions should the developer take? (Select TWO.)(Select 2)

    1. A.Create a new global secondary index with `orderStatus` as the partition key and `orderDate` as the sort key to support this specific access pattern directly
    2. B.Update application code to use `Query` with a key condition on the new index instead of `Scan` with a filter expression on `orderStatus`
    3. C.Add `orderStatus` as a projected attribute on the existing `customerId` GSI so `Scan` operations against that index run faster automatically
    4. D.Increase the table's on-demand throughput ceiling so `Scan` operations with a filter on `orderStatus` complete without consuming excessive capacity
    5. E.Rename the `orderStatus` attribute to `status` so DynamoDB automatically indexes it as part of the table's default primary key structure
    Show answer & explanation

    Correct answers: A, B — Create a new global secondary index with `orderStatus` as the partition key and `orderDate` as the sort key to support this specific access pattern directly; Update application code to use `Query` with a key condition on the new index instead of `Scan` with a filter expression on `orderStatus`

    • A. A GSI with `orderStatus` as the partition key and `orderDate` as the sort key lets the application run a `Query` targeted directly at matching orders, which is the standard way to support a new access pattern DynamoDB does not natively provide for a non-key attribute.
    • B. Creating the index only helps if the application actually queries it; switching the code from a table-wide `Scan` with a filter to a `Query` against the new index is what eliminates the cost of reading every item before filtering.
    • C. Projecting an attribute into an index changes what data is returned by queries against that index; it does not turn a `Scan` into a targeted lookup, and a `Scan` against any index still reads every item in that index before filtering.
    • D. Raising the throughput ceiling lets more expensive `Scan` operations complete without throttling, but it does not reduce the actual cost or latency of scanning the whole table; it treats the symptom rather than the access-pattern problem.
    • E. Renaming an attribute has no effect on indexing; DynamoDB does not automatically index arbitrary attributes regardless of their name, and only attributes explicitly defined as part of a primary key or secondary index are indexed.

    Subdomain 1.2: Develop code for AWS Lambda

    3.A developer is writing automated tests for a Lambda function that publishes messages to an SNS topic and writes items to a DynamoDB table. Which testing practices are appropriate for validating this function's AWS service integrations before deployment? (Select TWO.)(Select 2)

    1. A.Write unit tests that mock the SNS and DynamoDB SDK clients to verify the function calls them with the expected parameters
    2. B.Deploy the function to a staging environment and run integration tests that exercise a real SNS topic and DynamoDB table
    3. C.Skip testing the DynamoDB and SNS calls entirely, since AWS guarantees all SDK calls succeed once IAM permissions are granted
    4. D.Only test the function by manually inspecting the CloudFormation template, since template structure guarantees runtime correctness
    5. E.Rely exclusively on production traffic to reveal integration issues, since pre-deployment testing cannot catch SDK-level bugs
    Show answer & explanation

    Correct answers: A, B — Write unit tests that mock the SNS and DynamoDB SDK clients to verify the function calls them with the expected parameters; Deploy the function to a staging environment and run integration tests that exercise a real SNS topic and DynamoDB table

    • A. This is correct because mocking the SDK clients in unit tests isolates the function's logic and verifies it calls SNS and DynamoDB with the correct parameters, catching logic errors quickly without needing live infrastructure.
    • B. This is correct because integration tests against real staging resources validate that IAM permissions, request formats, and service behavior actually work end-to-end, catching issues that mocks cannot reveal, such as permission gaps or malformed requests.
    • C. This is incorrect because IAM permissions only authorize an API call; they do not guarantee the call succeeds, since malformed requests, throttling, or logic bugs can still cause failures that testing is meant to catch.
    • D. This is incorrect because reviewing a CloudFormation template only validates that resources are declared correctly; it says nothing about whether the function's runtime code correctly calls those services.
    • E. This is incorrect because waiting for production traffic to surface bugs is a reactive strategy that risks real customer impact; pre-deployment unit and integration testing are standard practices for catching these issues earlier.

    Subdomain 1.2: Develop code for AWS Lambda

    4.A Lambda function behind Amazon API Gateway needs to fetch a value from AWS AppConfig at the start of each invocation to check a feature flag, but repeated calls to AppConfig on every invocation add noticeable latency. Which approach reduces this latency while still integrating with AppConfig?

    1. A.Use the AWS AppConfig Lambda extension, which caches configuration data locally and serves it to the function over a local HTTP endpoint
    2. B.Call the AppConfig API directly from the handler on every invocation, since AppConfig responses are already cached by API Gateway automatically
    3. C.Store the feature flag value in the function's deployment package and redeploy the function each time the flag changes
    4. D.Move the feature flag check into a separate Lambda function invoked synchronously before every request to reduce AppConfig latency
    Show answer & explanation

    Correct answer: A — Use the AWS AppConfig Lambda extension, which caches configuration data locally and serves it to the function over a local HTTP endpoint

    • A. This is correct because the AWS AppConfig Lambda extension runs as a companion process that fetches and caches configuration data locally within the execution environment, letting the function's code retrieve values over a local endpoint instead of calling the AppConfig API remotely on every invocation.
    • B. This is incorrect because API Gateway does not cache AppConfig responses; API Gateway caching, if enabled, applies to the API's own method responses, not to calls a Lambda function separately makes to AppConfig.
    • C. This is incorrect because embedding the flag value in the deployment package requires a full redeploy for every flag change, defeating the purpose of using AppConfig for dynamic, redeploy-free configuration updates.
    • D. This is incorrect because adding a second synchronous Lambda invocation in the request path adds more latency and cost from an extra function call, rather than reducing the latency of retrieving configuration.

    Subdomain 1.2: Develop code for AWS Lambda

    5.A developer is implementing error handling inside a Lambda function's code that calls a flaky third-party payment API over HTTPS. Which coding practices reduce the chance of unnecessary failures being reported to callers or destinations? (Select TWO.)(Select 2)

    1. A.Wrap the third-party call in retry logic with exponential backoff and jitter for transient errors such as timeouts or 5xx responses
    2. B.Catch exceptions from the third-party call and distinguish retryable errors from non-retryable ones before deciding how to respond
    3. C.Let every exception propagate unhandled out of the handler, since Lambda automatically classifies and retries all errors identically
    4. D.Increase the function's memory to the maximum value, since higher memory automatically retries failed third-party API calls
    5. E.Suppress all exceptions silently and always return a success response, regardless of whether the payment call actually succeeded
    Show answer & explanation

    Correct answers: A, B — Wrap the third-party call in retry logic with exponential backoff and jitter for transient errors such as timeouts or 5xx responses; Catch exceptions from the third-party call and distinguish retryable errors from non-retryable ones before deciding how to respond

    • A. This is correct because implementing retry logic with exponential backoff and jitter inside the function's code for transient failures like timeouts or 5xx responses reduces unnecessary failures reported upward, since many such errors resolve on a short retry.
    • B. This is correct because distinguishing retryable errors (like network timeouts) from non-retryable ones (like a declined card) lets the function make an informed decision about whether to retry internally or fail fast and report accurately, avoiding wasted retries on errors that will never succeed.
    • C. This is incorrect because letting every exception propagate without any handling treats all failures identically, missing the opportunity to retry genuinely transient errors internally before they count against the function's overall retry or failure budget.
    • D. This is incorrect because memory configuration affects CPU allocation and cost; it has no relationship to retrying failed calls to an external payment API, which requires explicit application-level retry logic.
    • E. This is incorrect because silently suppressing exceptions and always reporting success would falsely tell callers a payment succeeded when it may not have, which is a dangerous correctness bug rather than sound error handling.

    Subdomain 1.1: Develop code for applications hosted on AWS

    6.A developer is writing code that publishes to an Amazon SNS topic and wants only a subset of subscribers to receive certain messages, based on attributes of the message rather than its full body. Which three statements about implementing this correctly are accurate?(Select 3)

    1. A.Message attributes, such as an eventType key-value pair, can be set at publish time so a filter policy evaluates them without parsing the body.
    2. B.A subscription filter policy is attached to the individual subscription, so different subscribers to one topic can each filter on different criteria.
    3. C.Subscribers whose filter policy does not match the message attributes simply do not receive that particular message, while matching subscribers still do.
    4. D.Filter policies can only match on the full message body text and can never evaluate individual message attributes at all.
    5. E.Every subscriber to an SNS topic always receives every message published to that topic regardless of any filter policy configured.
    6. F.Filter policies must be defined once per topic and automatically apply identically to every current and future subscription.
    Show answer & explanation

    Correct answers: A, B, C — Message attributes, such as an eventType key-value pair, can be set at publish time so a filter policy evaluates them without parsing the body.; A subscription filter policy is attached to the individual subscription, so different subscribers to one topic can each filter on different criteria.; Subscribers whose filter policy does not match the message attributes simply do not receive that particular message, while matching subscribers still do.

    • A. Setting message attributes at publish time gives filter policies structured key-value data to evaluate directly, without needing to parse the message body to determine routing.
    • B. Because the filter policy lives on each individual subscription, different subscribers to the same topic can independently define their own criteria for which messages they receive.
    • C. This describes the core selective-delivery behavior of SNS filtering: a message is only delivered to subscribers whose filter policy matches its attributes, and skipped for the rest.
    • D. SNS filter policies are commonly evaluated against message attributes, and body-based filtering support exists separately, so restricting filtering to body text only is not an accurate description.
    • E. This contradicts the purpose of filter policies entirely; when a filter policy is configured, only subscribers whose policy matches actually receive a given message, not every subscriber.
    • F. Filter policies are configured per subscription rather than once per topic, so they do not automatically and identically apply to every current and future subscription on that topic.

    Subdomain 1.1: Develop code for applications hosted on AWS

    7.A Python Lambda function uses boto3 to call the DynamoDB API and occasionally receives a ProvisionedThroughputExceededException during traffic spikes. The developer wants the SDK to automatically retry these throttling errors using a backoff strategy without writing custom retry loops. What should the developer do?

    1. A.Configure the boto3 client with a retry mode, such as standard or adaptive, applying automatic exponential backoff to retryable throttling errors.
    2. B.Wrap every DynamoDB call in a try and except block that immediately re-raises the exception straight back to the caller.
    3. C.Increase the DynamoDB table's read and write capacity units to their absolute maximum value in order to eliminate throttling.
    4. D.Set the Lambda function's timeout to the fifteen-minute maximum so the retries always complete before the function is stopped.
    Show answer & explanation

    Correct answer: A — Configure the boto3 client with a retry mode, such as standard or adaptive, applying automatic exponential backoff to retryable throttling errors.

    • A. Configuring a boto3 retry mode enables the SDK's built-in exponential backoff for retryable errors such as throttling, which is exactly the automatic behavior the developer wants without custom retry code.
    • B. Immediately re-raising the exception provides no retry behavior at all, so the throttling error would simply propagate to the caller instead of being automatically retried.
    • C. Raising capacity to its maximum does not by itself configure the SDK's retry behavior, and this is a costly, table-level change rather than an SDK-level retry configuration in application code.
    • D. Extending the function's timeout gives more wall-clock time overall but does nothing to configure automatic backoff retries for throttling errors from the DynamoDB SDK calls themselves.

    Subdomain 1.1: Develop code for applications hosted on AWS

    8.A developer is writing a Node.js application that must call several AWS services using the AWS SDK, and the application will run on an EC2 instance in a private subnet with an attached IAM instance profile. Which credential-resolution behavior should the developer rely on to avoid hardcoding access keys?

    1. A.The AWS SDK automatically retrieves temporary credentials from the instance metadata service based on the role attached to the instance profile.
    2. B.The developer must store the instance's IAM role access key and secret key as environment variables before the SDK can authenticate.
    3. C.The AWS SDK requires a dotfile credentials file with a long-term access key manually copied onto every single EC2 instance.
    4. D.The developer must call sts colon AssumeRole explicitly in application code before every single AWS SDK call the application makes.
    Show answer & explanation

    Correct answer: A — The AWS SDK automatically retrieves temporary credentials from the instance metadata service based on the role attached to the instance profile.

    • A. The SDK's default credential provider chain automatically fetches short-lived credentials from the instance metadata service for the role attached to the instance profile, requiring no hardcoded keys in application code.
    • B. IAM roles do not expose a static access key and secret key to be copied into environment variables; the whole point of an instance profile is that the SDK retrieves temporary credentials automatically instead.
    • C. A manually distributed credentials file with long-term keys is precisely the hardcoded-key pattern that using an IAM instance profile is meant to avoid on EC2 instances.
    • D. The SDK's credential provider chain already resolves temporary credentials from the instance profile automatically, so explicitly calling AssumeRole before every single call is unnecessary extra code.

    Domain 2: Security

    Subdomain 2.1: Implement authentication and/or authorization for applications and AWS services

    9.A single-page web application authenticates users through a Cognito user pool and then calls a REST API hosted on Amazon API Gateway to fetch order history. The API must reject any request that does not carry a valid, unexpired token from that sign-in. How should the application present its credentials on each API call?

    1. A.Send the Cognito access token in the `Authorization` header as a bearer token on every request to the API.
    2. B.Send the user's original plaintext password in a custom header so the API can re-verify it against the user pool on each call.
    3. C.Embed the refresh token in the URL query string of each API request so the API can exchange it for a new session on demand.
    4. D.Store the user's session state in a server-side cookie on the API Gateway service itself and skip sending any token from the client.
    Show answer & explanation

    Correct answer: A — Send the Cognito access token in the `Authorization` header as a bearer token on every request to the API.

    • A. A bearer token in the Authorization header is the standard OAuth 2.0 pattern, and a Cognito access token carries the scopes an API Gateway authorizer needs to validate the request without re-checking the password.
    • B. Resending the plaintext password on every call multiplies the exposure of a long-term credential and defeats the purpose of issuing short-lived tokens after a single sign-in.
    • C. Refresh tokens are meant to be exchanged privately for new access tokens through a token endpoint, not attached to every API call, and query strings are frequently logged by proxies and browsers.
    • D. API Gateway is a managed, mostly stateless service and does not maintain per-user server-side session cookies, so the client must present a verifiable token on each request.

    Subdomain 2.1: Implement authentication and/or authorization for applications and AWS services

    10.An operator runs `aws sts assume-role` from the CLI to switch into `RoleA` in another account, then immediately tries to use those short-term credentials to assume a second role, `RoleB`, requesting a 12-hour `DurationSeconds` for the RoleB session. What happens?

    1. A.The second AssumeRole call fails, because role chaining caps a session at one hour regardless of the requested duration or either role's configured maximum.
    2. B.The second AssumeRole call succeeds with the full 12-hour session, since RoleB's own maximum session duration setting is the only limit that applies.
    3. C.The second AssumeRole call is rejected outright, because AWS never permits a role's temporary credentials to be used to assume any other role.
    4. D.The second AssumeRole call succeeds, but the resulting RoleB session automatically inherits the exact same permissions as RoleA instead of using RoleB's own attached policy.
    Show answer & explanation

    Correct answer: A — The second AssumeRole call fails, because role chaining caps a session at one hour regardless of the requested duration or either role's configured maximum.

    • A. When credentials from an already-assumed role are used to assume a second role, that is role chaining, and AWS caps the resulting session at a maximum of one hour regardless of the requested duration or any role's configured maximum.
    • B. RoleB's own maximum session duration setting is not the limiting factor here; the one-hour role-chaining cap applies on top of it whenever the calling credentials already came from an assumed role.
    • C. Using one role's temporary credentials to assume a different role is a supported and common pattern called role chaining; it is limited in duration, not disallowed.
    • D. A successfully assumed role session takes on the permissions defined by that role's own permissions policy, not the permissions of whichever role's credentials were used to make the AssumeRole call.

    Subdomain 2.1: Implement authentication and/or authorization for applications and AWS services

    11.A microservice needs a database password to connect to an RDS instance, and the security team requires that this credential be rotated automatically on a schedule without any manual redeployment of the microservice's code. Which two AWS capabilities together satisfy this requirement?(Select 2)

    1. A.Store the database credential in AWS Secrets Manager and enable its built-in automatic rotation feature for the RDS-compatible secret type.
    2. B.Grant the microservice's IAM role permission to call `secretsmanager:GetSecretValue` so it retrieves the current value at runtime.
    3. C.Hardcode the database password directly into the microservice's source code and redeploy the service manually every time the password changes.
    4. D.Store the database password in an environment variable set once at container build time, and never update that value after the image is built.
    5. E.Disable authentication on the RDS instance entirely so the microservice can connect without needing to know any password at all.
    Show answer & explanation

    Correct answers: A, B — Store the database credential in AWS Secrets Manager and enable its built-in automatic rotation feature for the RDS-compatible secret type.; Grant the microservice's IAM role permission to call `secretsmanager:GetSecretValue` so it retrieves the current value at runtime.

    • A. Secrets Manager's built-in rotation feature for RDS-compatible secrets automatically updates the credential on a schedule and coordinates the change with the database, without requiring anyone to redeploy application code.
    • B. Granting the microservice's role permission to fetch the secret at runtime means the application always retrieves the current rotated value instead of relying on a stale value baked into its configuration or code.
    • C. Hardcoding the password and redeploying manually on every rotation is exactly the manual redeployment burden the requirement is trying to eliminate, and it embeds a static secret in source code.
    • D. A password baked into an environment variable at build time becomes stale the moment the credential rotates, since the running containers have no way to pick up the new value without a rebuild and redeploy.
    • E. Disabling authentication on the database entirely removes any access control on the data store, which is a severe security regression rather than a solution to credential rotation.

    Subdomain 2.3: Manage sensitive data in application code

    12.A developer must choose a service to store a database password that needs automatic periodic rotation without manual application redeployment. Which service is purpose-built for this requirement?

    1. A.AWS Secrets Manager, which supports configuring an automatic rotation schedule backed by a rotation Lambda function for supported credentials.
    2. B.Systems Manager Parameter Store SecureString, which natively rotates stored values on a schedule without needing any additional Lambda function.
    3. C.AWS AppConfig, which is built for feature flag rollout and configuration deployment, not for credential storage or automatic rotation.
    4. D.Amazon S3 with server-side encryption enabled, which stores the password as an encrypted object but includes no built-in rotation mechanism.
    Show answer & explanation

    Correct answer: A — AWS Secrets Manager, which supports configuring an automatic rotation schedule backed by a rotation Lambda function for supported credentials.

    • A. AWS Secrets Manager offers configurable automatic rotation schedules and native integrations that invoke a rotation Lambda function for supported credential types, matching this requirement directly.
    • B. Parameter Store SecureString parameters encrypt values with KMS but do not natively rotate them on a schedule; rotation would require custom automation outside the service.
    • C. AWS AppConfig targets feature flags and configuration deployments with validation and rollback, not credential storage or automatic secret rotation.
    • D. Storing a password as an encrypted S3 object provides encryption at rest but has no built-in scheduling or mechanism for rotating the credential automatically.

    Subdomain 2.3: Manage sensitive data in application code

    13.A multi-tenant application uses per-tenant IAM roles assumed via STS to access a shared DynamoDB table, and the team wants to prevent one tenant's role from ever reading another tenant's items even if application code has a bug. Which two mechanisms help enforce this at the AWS access-control layer? (Select TWO.)(Select 2)

    1. A.Attach an IAM policy condition that restricts `dynamodb:LeadingKeys` to the tenant identifier embedded in the caller's session tags.
    2. B.Pass the tenant identifier as a session tag when assuming the tenant-scoped role, then reference that tag in the table's IAM policy condition.
    3. C.Rely solely on the application's business logic to filter query results by tenant identifier after retrieving all items from the shared table.
    4. D.Grant every tenant's role the same broad `dynamodb:*` permission on the entire table, since STS AssumeRole enforces isolation automatically.
    5. E.Store every tenant's data in the same partition key value, since shared partitions make application-level filtering unnecessary.
    Show answer & explanation

    Correct answers: A, B — Attach an IAM policy condition that restricts `dynamodb:LeadingKeys` to the tenant identifier embedded in the caller's session tags.; Pass the tenant identifier as a session tag when assuming the tenant-scoped role, then reference that tag in the table's IAM policy condition.

    • A. A `dynamodb:LeadingKeys` condition tied to the session's tenant tag restricts DynamoDB itself to only return items whose partition key matches that tenant, enforcing isolation independent of application code.
    • B. Passing the tenant identifier as a session tag during AssumeRole gives the IAM policy a verified value to match against, letting the access-control layer enforce tenant scoping consistently.
    • C. Filtering only in application logic after data has already been retrieved does not prevent a bug from returning or acting on another tenant's items, since the access control happens too late.
    • D. STS AssumeRole issues temporary credentials but does not itself scope permissions; granting broad `dynamodb:*` access on the whole table would let a role read every tenant's data.
    • E. Placing every tenant's data under the same partition key value removes the very attribute that IAM condition keys and query logic rely on to separate tenants.

    Subdomain 2.3: Manage sensitive data in application code

    14.A regulated multi-tenant application must guarantee that if one tenant's encryption key were ever compromised, only that tenant's data would be at risk, not any other tenant's data. Which encryption key strategy achieves this isolation?

    1. A.Encrypt every tenant's data using the same AWS managed KMS key `aws/dynamodb`, since a single shared key simplifies key management significantly.
    2. B.Provision a separate customer managed KMS key per tenant, so a compromise of one tenant's key cannot be used to decrypt another tenant's data.
    3. C.Store all tenants' data unencrypted at rest, relying entirely on network-level TLS encryption in transit to protect sensitive information.
    4. D.Rotate a single shared KMS key more frequently for all tenants, since more frequent rotation eliminates the risk of one tenant's key compromise.
    Show answer & explanation

    Correct answer: B — Provision a separate customer managed KMS key per tenant, so a compromise of one tenant's key cannot be used to decrypt another tenant's data.

    • A. A single shared key means compromising that one key would expose every tenant's data, which is exactly the blast-radius outcome the requirement is meant to prevent.
    • B. Provisioning a separate customer managed key per tenant confines the impact of a key compromise to that one tenant's data, since no other tenant's data was ever encrypted with the compromised key.
    • C. Leaving data unencrypted at rest removes at-rest protection entirely; TLS only protects data while it is moving over the network, not while it is stored.
    • D. Rotating a single shared key more often still leaves all tenants dependent on that one key at any given time, so a compromise during an active rotation period still exposes every tenant.

    Subdomain 2.2: Implement encryption by using AWS services

    15.A developer running local integration tests needs a temporary TLS certificate and a matching SSH key pair purely for a development environment that will never be exposed to production traffic. Which approach is appropriate for this development-only use case?

    1. A.Request a publicly trusted certificate from AWS Certificate Manager and export its private key for use in the local development environment
    2. B.Generate a self-signed certificate and an SSH key pair locally using OpenSSL or `ssh-keygen`, since these artifacts never need public trust or long-term management
    3. C.Ask the security team to issue the SSH key pair from AWS Secrets Manager, since Secrets Manager can generate SSH key material directly
    4. D.Provision a full AWS Private CA hierarchy just for this developer's laptop, since certificate generation must always go through a fully managed certificate authority
    Show answer & explanation

    Correct answer: B — Generate a self-signed certificate and an SSH key pair locally using OpenSSL or `ssh-keygen`, since these artifacts never need public trust or long-term management

    • A. Public ACM certificates are designed for use within AWS with integrated services, and their private keys for ACM-issued certificates are not exportable, so this approach does not fit a standalone local development scenario.
    • B. For a purely local, disposable development environment, generating a self-signed certificate and an SSH key pair with standard command-line tools is the simplest option and needs no managed AWS service.
    • C. AWS Secrets Manager stores and rotates secret values but does not generate SSH key pairs or certificates itself, so it cannot produce the key material this scenario needs.
    • D. Standing up an entire private certificate authority hierarchy is a heavyweight, ongoing-cost solution meant for organizational internal trust, unnecessary overhead for one developer's disposable local testing artifacts.

    Subdomain 2.2: Implement encryption by using AWS services

    16.A security team wants to encrypt environment variables for a Lambda function containing a third-party API key, going beyond the default encryption Lambda already applies. What is the most direct way to add an additional layer of protection using a customer managed KMS key?

    1. A.Rename the environment variable using a prefix that Lambda recognizes as sensitive, which triggers automatic KMS encryption for that value only
    2. B.Store the API key inside the Lambda deployment package itself as plaintext, since the deployment package is already encrypted at rest by S3
    3. C.Disable environment variables entirely and hardcode the API key directly into the function's source code to avoid encryption concerns altogether
    4. D.Configure the function to use a customer managed KMS key for its environment variables, which also enables console helpers to encrypt values
    Show answer & explanation

    Correct answer: D — Configure the function to use a customer managed KMS key for its environment variables, which also enables console helpers to encrypt values

    • A. Lambda does not infer sensitivity from a variable name prefix; encryption of environment variables is configured at the function level with a KMS key selection, not through naming conventions.
    • B. Placing the key as plaintext in the deployment package means anyone who can view the package or source can read the secret directly, and S3's storage encryption does not protect the value within the function code itself.
    • C. Hardcoding a secret into source code makes it visible to anyone with code access and typically ends up committed to version control, which is a worse security posture than an encrypted environment variable.
    • D. Lambda supports specifying a customer managed KMS key for environment variable encryption instead of the default AWS managed key, and this also unlocks the console's helper to encrypt individual values before display.

    Subdomain 2.2: Implement encryption by using AWS services

    17.A team is choosing between DNS validation and email validation when requesting a public certificate from AWS Certificate Manager for a domain they manage in Amazon Route 53. Which two statements correctly compare the two validation methods? (Select TWO.)(Select 2)

    1. A.DNS validation cannot be used at all if the domain's DNS is hosted in Amazon Route 53, since Route 53 blocks the required record type from being added
    2. B.DNS validation lets ACM automatically renew the certificate indefinitely as long as that required CNAME record stays in the hosted zone unchanged
    3. C.Email validation requires a person to click a confirmation link sent to domain contacts, which must be repeated for renewal unless the team switches
    4. D.Both validation methods produce a certificate with identical renewal behavior, since ACM ignores which validation method was originally used
    5. E.Email validation is generally faster to complete than DNS validation because it does not require access to modify any DNS records
    Show answer & explanation

    Correct answers: B, C — DNS validation lets ACM automatically renew the certificate indefinitely as long as that required CNAME record stays in the hosted zone unchanged; Email validation requires a person to click a confirmation link sent to domain contacts, which must be repeated for renewal unless the team switches

    • A. DNS validation is fully supported, and in fact simplified, when a domain is hosted in Route 53, since ACM can add the required validation record automatically, so this statement about Route 53 blocking it is false.
    • B. Once the CNAME validation record is in place, ACM can automatically re-validate and renew the certificate without any manual action, which is the main operational advantage of DNS validation.
    • C. Email validation depends on a person receiving and clicking a link at the time of issuance, and because it is not automated the same way DNS validation is, renewals can require repeating that manual step, making this correct.
    • D. The two methods do differ in renewal behavior, since DNS-validated certificates can renew automatically via the existing record while email-validated ones may require repeated manual confirmation, so claiming identical behavior is false.
    • E. Email validation is not inherently faster; it depends on someone checking their inbox and clicking a link, whereas DNS validation with Route 53 access can complete automatically and quickly, so this comparison is incorrect.

    Domain 3: Deployment

    Subdomain 3.1: Prepare application artifacts to be deployed to AWS

    18.A developer writes a Python Lambda function and stores the handler at `src/handlers/process_order.py`, defining `def handle(event, context):`. The function configuration currently sets the handler value to `process_order.handle`, and invocations fail with an import error. What handler value correctly matches this directory structure?

    1. A.`src/handlers/process_order.handle`, matching the module's exact file path relative to the deployment package root.
    2. B.`process_order.handle`, because Lambda always searches every subdirectory of the package for a matching filename.
    3. C.`handle.process_order`, because Lambda handler values name the function first and the containing module second.
    4. D.`src.handlers.process_order.handle`, because Lambda substitutes path separators with periods only for the top-level directory.
    Show answer & explanation

    Correct answer: A — `src/handlers/process_order.handle`, matching the module's exact file path relative to the deployment package root.

    • A. Lambda resolves the handler as `<path-to-module>.<function-name>` relative to the root of the deployment package, so a handler file at `src/handlers/process_order.py` must be referenced as `src/handlers/process_order.handle` for the import to succeed.
    • B. Lambda does not recursively search subdirectories for a matching filename; it imports the exact module path given in the handler setting, so a bare filename fails when the file lives in a nested directory.
    • C. The handler value always names the importable module path before the function name, never the reverse, so swapping the order produces an import error rather than resolving the nested file correctly.
    • D. Lambda does not selectively convert only the first path segment; the module path portion of the handler value must reflect the full relative path with the separators the runtime's import mechanism expects.

    Subdomain 3.1: Prepare application artifacts to be deployed to AWS

    19.A team is packaging its application artifact and must decide what belongs inside the deployment package versus what should be retrieved from an external AWS service at runtime. Which items are appropriate to bundle directly inside the deployment package? (Select TWO.)(Select 2)

    1. A.The application's compiled or interpreted source code files that implement the handler and business logic.
    2. B.Third-party library dependencies the application imports, installed into the package's dependency directory.
    3. C.Database credentials and API keys the application uses to authenticate to downstream services.
    4. D.Feature flag values that product managers expect to toggle without waiting for a new deployment.
    5. E.The current day's exchange rate table that an external pricing job refreshes every few hours.
    Show answer & explanation

    Correct answers: A, B — The application's compiled or interpreted source code files that implement the handler and business logic.; Third-party library dependencies the application imports, installed into the package's dependency directory.

    • A. The application's own source files are the core of the deployment package by definition; without them there is no code for Lambda or the compute service to execute.
    • B. Installed third-party dependencies must be present in the package's dependency directory (such as `node_modules` or a Python site-packages folder) because the execution environment does not install them for you.
    • C. Credentials belong in Secrets Manager or Parameter Store and should be retrieved at runtime with least-privilege IAM permissions, not embedded in the package where they would sit in version control and build artifacts.
    • D. Feature flags are meant to change without a redeploy, so they belong in a service like AppConfig that the application queries at runtime rather than in values baked into the shipped artifact.
    • E. Data that changes on its own schedule outside the application's release cycle, like a frequently refreshed exchange rate table, should be fetched from its source at runtime rather than frozen into a static artifact.

    Subdomain 3.3: Automate deployment testing

    20.A CI/CD pipeline needs to deploy API Gateway changes to `dev` on every commit, but only promote to `staging` and `prod` after manual approval. Which two pipeline design choices support this correctly?(Select 2)

    1. A.Grant the pipeline's role permission to auto-delete the production API whenever a dev deployment fails
    2. B.Add a manual approval action between the `dev` stage and the `staging`/`prod` deployment actions
    3. C.Merge all three environments into a single CloudFormation stack so one deploy updates them together
    4. D.Skip CodeBuild for staging and prod, relying on developers to run `create-deployment` by hand
    5. E.Parameterize the SAM deployment step with a stage name so one template deploys any of the stages
    6. F.Trigger the pipeline only from `main`, even for feature-branch commits meant to reach `dev`
    Show answer & explanation

    Correct answers: B, E — Add a manual approval action between the `dev` stage and the `staging`/`prod` deployment actions; Parameterize the SAM deployment step with a stage name so one template deploys any of the stages

    • A. Automatically deleting production based on a dev failure is destructive and unrelated to gating promotion with approvals.
    • B. A manual approval gate is the standard CodePipeline mechanism to require human sign-off before changes reach staging and production.
    • C. A single shared stack for all three environments removes the isolation needed to test dev changes independently before promoting them.
    • D. Bypassing the build tool for staging and prod removes the pipeline's automated, repeatable deployment path in favor of error-prone manual commands.
    • E. Parameterizing the deployment with a stage name lets one IaC template be reused across dev, staging, and prod without duplicating the definition.
    • F. Restricting every environment's trigger to main prevents feature-branch commits from reaching dev at all, blocking the intended per-commit dev deployment.

    Subdomain 3.3: Automate deployment testing

    21.A frontend team on AWS Amplify and a backend team on AWS Copilot both need environments that map to approved code versions for integration testing before merging to production. Which two statements correctly describe how each service supports this?(Select 2)

    1. A.Amplify branch environments share one database and storage bucket with production, with no way to isolate them
    2. B.Copilot environments must all reside in the same VPC as production, since separate VPCs aren't supported
    3. C.Amplify can automatically host a separate environment for each connected Git branch, like `develop` or `staging`
    4. D.Amplify requires manually provisioning a brand-new AWS account for every additional branch environment
    5. E.Copilot environments can only be created via the console; the CLI has no environment-creation command
    6. F.Copilot lets a team create named environments, such as `test`, each with its own infrastructure and service versions
    Show answer & explanation

    Correct answers: C, F — Amplify can automatically host a separate environment for each connected Git branch, like `develop` or `staging`; Copilot lets a team create named environments, such as `test`, each with its own infrastructure and service versions

    • A. Amplify branch environments can be configured with their own backend resources and are not forced to share a single database or bucket with production.
    • B. Copilot supports placing environments in different VPCs; production isolation across VPCs is a common and supported pattern, not a restriction.
    • C. Amplify's branch-based deployment model spins up an isolated hosting environment per connected branch, which is how teams typically map git branches like develop or staging to test environments.
    • D. Amplify branch environments are hosted within the existing Amplify app and do not require provisioning a separate AWS account per branch.
    • E. The Copilot CLI includes commands such as `copilot env init` specifically for creating environments; console-only creation is not accurate.
    • F. Copilot's environment concept explicitly provisions its own infrastructure per named environment, letting a team deploy an approved service version into a test environment separate from production.

    Subdomain 3.4: Deploy code by using AWS Continuous Integration and Continuous Delivery (CI/CD) services

    22.A team wants every merge to the `main` branch of its AWS CodeCommit repository to automatically start a CodePipeline execution, without anyone manually clicking a button in the console. Which configuration achieves this?

    1. A.Configure the pipeline's Source stage with the CodeCommit repository and branch, which creates an Amazon EventBridge rule that starts the pipeline on new commits.
    2. B.Schedule an Amazon EventBridge cron rule that polls the repository's commit history every five minutes and manually calls `StartPipelineExecution`.
    3. C.Add an IAM policy to every developer's user that requires them to run `aws codepipeline start-pipeline-execution` immediately after every `git push`.
    4. D.Attach an S3 event notification to the repository so that each commit object written to S3 triggers a Lambda function that starts the pipeline.
    Show answer & explanation

    Correct answer: A — Configure the pipeline's Source stage with the CodeCommit repository and branch, which creates an Amazon EventBridge rule that starts the pipeline on new commits.

    • A. When a CodePipeline Source stage is configured against a CodeCommit repository and branch, CodePipeline provisions an EventBridge rule that automatically detects new commits on that branch and starts an execution, requiring no manual trigger.
    • B. A custom polling cron rule duplicates functionality CodePipeline already provisions natively for CodeCommit sources and adds unnecessary latency and complexity compared to the built-in change-detection integration.
    • C. Requiring every developer to manually invoke a CLI command after pushing is error-prone and defeats the purpose of automatic triggering; it is not how CodePipeline is designed to detect source changes.
    • D. CodeCommit repositories are not backed by S3 objects that emit S3 event notifications; this describes a mechanism that does not apply to how CodeCommit integrates with CodePipeline.

    Subdomain 3.4: Deploy code by using AWS Continuous Integration and Continuous Delivery (CI/CD) services

    23.A CodeBuild project needs to install dependencies, run the unit test suite, and then package a Lambda deployment artifact, with each step clearly separated so a failed test run stops before packaging happens. How should these steps be organized in the project's build specification?

    1. A.Define separate `install`, `pre_build`, and `build` phases in `buildspec.yml`, placing the test command in `pre_build` so a failure stops the build before packaging runs.
    2. B.Write a single shell script that installs dependencies, runs tests, and packages the artifact in one sequential block inside the `artifacts` section of `buildspec.yml`.
    3. C.Create three separate CodeBuild projects and chain them using S3 object versioning so each project overwrites the same key when its step finishes.
    4. D.Put the test command inside the CodeBuild project's environment variables so it executes automatically before the buildspec phases are evaluated.
    Show answer & explanation

    Correct answer: A — Define separate `install`, `pre_build`, and `build` phases in `buildspec.yml`, placing the test command in `pre_build` so a failure stops the build before packaging runs.

    • A. CodeBuild's `buildspec.yml` phases run in order, and by default a failing command in an earlier phase like `pre_build` stops the build, so placing tests in `pre_build` before the `build` phase packages the artifact correctly separates and gates the steps.
    • B. The `artifacts` section only describes which files to collect as build output after phases complete; it is not a place to run shell commands, so this structure would not execute or gate anything correctly.
    • C. Chaining three separate projects through S3 overwrites is a fragile, manual workaround for something CodeBuild already supports natively through ordered buildspec phases within a single project.
    • D. Environment variables hold static or parameter-derived values available to the build; they are not executed as commands and cannot run a test suite before the buildspec phases begin.

    Subdomain 3.4: Deploy code by using AWS Continuous Integration and Continuous Delivery (CI/CD) services

    24.A team is designing a CodePipeline workflow that must build code, run automated tests, deploy to a staging environment for QA sign-off, then deploy to production only after a human explicitly approves the release. Which components should the pipeline include? (Select THREE.)(Select 3)

    1. A.A build stage using CodeBuild that compiles the application and runs the automated test suite before any deployment action runs.
    2. B.A deploy stage targeting the staging environment, positioned before the manual approval stage in the pipeline's sequence of stages.
    3. C.A manual approval action configured between the staging and production deploy stages, which pauses execution until someone approves it.
    4. D.A second, entirely independent pipeline dedicated only to production, manually started by a developer after staging tests pass.
    5. E.An IAM policy statement inside the buildspec.yml file that grants the QA team console access to click the approval button.
    Show answer & explanation

    Correct answers: A, B, C — A build stage using CodeBuild that compiles the application and runs the automated test suite before any deployment action runs.; A deploy stage targeting the staging environment, positioned before the manual approval stage in the pipeline's sequence of stages.; A manual approval action configured between the staging and production deploy stages, which pauses execution until someone approves it.

    • A. Correct: a build stage backed by CodeBuild running compilation and the automated test suite is the standard way to gate later deploy stages on passing tests before anything reaches staging or production.
    • B. Correct: deploying to staging before the approval stage lets QA validate the release candidate in a real environment, which is the input the human approver needs before signing off on production.
    • C. Correct: CodePipeline's manual approval action type pauses the pipeline execution at that stage until a designated approver explicitly approves or rejects it, which is exactly the gate this workflow requires.
    • D. Incorrect: splitting production into a second independent pipeline manually triggered by a developer bypasses the orchestrated, auditable staged workflow that a single pipeline with a built-in approval action already provides.
    • E. Incorrect: IAM policies control API-level permissions and are configured on roles or users, not embedded as statements inside a buildspec.yml file, and they do not grant console button access on their own.

    Subdomain 3.2: Test applications in development environments

    25.A developer is unit testing a Lambda function that will be triggered by an Amazon SQS queue, but the queue and function are not deployed yet. They need a realistic sample event structure matching what SQS sends to Lambda, to use as a local test payload. What should they do?

    1. A.Run `sam local generate-event sqs receive-message` to produce a sample SQS-to-Lambda event payload, then redirect it into a JSON file for local invocation.
    2. B.Run `sam local start-lambda` and then immediately send a carefully handwritten payload to its emulated invoke endpoint using the official AWS SDK's `invoke` call.
    3. C.Deploy the queue and function together with `sam deploy`, send a real test message, then copy the resulting CloudWatch Logs entry as the event.
    4. D.Open the Lambda console's built-in DynamoDB Streams template and carefully edit its field names until they resemble an SQS message body.
    Show answer & explanation

    Correct answer: A — Run `sam local generate-event sqs receive-message` to produce a sample SQS-to-Lambda event payload, then redirect it into a JSON file for local invocation.

    • A. The SAM CLI's event generator ships built-in templates for common event sources, including SQS, so it can produce a structurally correct sample payload without deploying anything.
    • B. Starting the local invoke endpoint still requires the developer to already have a correctly shaped payload; it does not generate the SQS event structure itself.
    • C. Deploying resources just to capture a sample payload defeats the purpose of testing before deployment and is unnecessary since a built-in event template already exists.
    • D. DynamoDB Streams records use a different shape than SQS messages, so manually reshaping one into the other risks producing an inaccurate test payload.

    Subdomain 3.2: Test applications in development environments

    26.A team is deciding how to validate a Lambda function that writes records to DynamoDB and publishes a message to an SNS topic. They are debating whether to test with mocks or against real deployed resources in a cloud sandbox account. Which two statements correctly describe the tradeoff? (Select TWO)(Select 2)

    1. A.Testing against real deployed resources verifies the function's IAM permissions and service quotas, which mocked SDK calls cannot validate.
    2. B.Mock-based tests generally run faster and do not require network access, making them well suited for exercising business logic in isolation.
    3. C.Mocked tests automatically stay in sync with the vendor's current API response schema, so they never need any updates after an SDK upgrade occurs.
    4. D.Tests that rely only on mocks are guaranteed to also pass when the same code is deployed and invoked in a live AWS account.
    5. E.Testing exclusively in the cloud eliminates the need to write any unit tests for the function's internal business logic.
    Show answer & explanation

    Correct answers: A, B — Testing against real deployed resources verifies the function's IAM permissions and service quotas, which mocked SDK calls cannot validate.; Mock-based tests generally run faster and do not require network access, making them well suited for exercising business logic in isolation.

    • A. Only a real deployment can confirm the execution role actually has the DynamoDB and SNS permissions it needs, and that the account's service quotas allow the operation to succeed.
    • B. Because mocks avoid real network calls, they execute quickly and are useful for exercising the function's internal logic in isolation from AWS service behavior.
    • C. Mocks are static and must be manually updated whenever the underlying API's request or response schema changes; they do not track vendor changes automatically.
    • D. A mock-only test can pass while the real deployment fails, for example due to a missing IAM permission or an incorrect table name, so passing mocks are not a deployment guarantee.
    • E. Cloud-based testing validates configuration and integration behavior, but it does not remove the value of fast, isolated unit tests for internal business logic.

    Subdomain 3.2: Test applications in development environments

    27.A team wants to gradually validate a new API Gateway deployment against a small slice of live traffic on the `prod` stage before fully promoting it, while keeping the ability to roll back quickly if error rates rise. Which two actions correctly describe how to set this up? (Select TWO)(Select 2)

    1. A.Enable canary settings on the `prod` stage and set a traffic percentage so a small share of requests route to the new deployment while the rest continue to baseline.
    2. B.Configure CloudWatch alarms on the canary's error rate and latency metrics so the team can detect problems before promoting the canary to 100% of traffic.
    3. C.Create an entirely new, fully separate REST API solely for the canary release and manually update every client application to start calling that new invoke URL instead.
    4. D.Disable stage variables on the canary so that its Lambda integration always points at the same alias as the stable baseline deployment.
    5. E.Delete the `prod` stage and recreate it from the new deployment immediately, since API Gateway stages do not support partial traffic shifting.
    Show answer & explanation

    Correct answers: A, B — Enable canary settings on the `prod` stage and set a traffic percentage so a small share of requests route to the new deployment while the rest continue to baseline.; Configure CloudWatch alarms on the canary's error rate and latency metrics so the team can detect problems before promoting the canary to 100% of traffic.

    • A. API Gateway's canary release settings let a configured percentage of a stage's traffic reach a new deployment while the remainder continues to the current baseline, exactly the gradual validation the team wants.
    • B. Watching canary-specific error and latency metrics with alarms gives the team an early signal to hold or roll back the canary before it is promoted to handle all traffic.
    • C. A canary release is designed to avoid client-facing URL changes entirely, so standing up a second API and updating every caller defeats the purpose of a gradual, transparent rollout.
    • D. Canary settings support overriding stage variables specifically so the canary deployment can point at a different backend alias than the baseline, which is often required for meaningful canary testing.
    • E. API Gateway stages explicitly support canary settings for partial traffic shifting, so recreating the stage from scratch is unnecessary and discards the ability to compare against a stable baseline.

    Domain 4: Troubleshooting and Optimization

    Subdomain 4.1: Assist in a root cause analysis

    28.A Python Lambda function has started returning `500` errors intermittently. The engineer wants to find the exact exception type and stack trace CloudWatch Logs captured for the failing invocations from the last two hours. Which action is most direct?

    1. A.Open the function's CloudWatch Logs Insights log group and run a query filtering `@message` for `Traceback` or `ERROR`, then inspect the matching log entries for the exception type and stack trace lines.
    2. B.Open AWS X-Ray and read the segment's `http.response.status` field, since X-Ray is incorrectly assumed to capture the full Python stack trace for every 500 response by default automatically.
    3. C.Re-deploy the Lambda function with extra `print()` debug statements added around the suspected failing code path, then wait patiently for the intermittent error to recur again before checking the logs once more.
    4. D.Open the Lambda function's configuration page and check the Monitoring tab's error count graph, which is incorrectly assumed to list the exception message text for each observed error spike.
    Show answer & explanation

    Correct answer: A — Open the function's CloudWatch Logs Insights log group and run a query filtering `@message` for `Traceback` or `ERROR`, then inspect the matching log entries for the exception type and stack trace lines.

    • A. Filtering the log messages for Python's traceback marker or an error-level tag surfaces the exact log entries containing the exception type and stack trace, which is the fastest direct path to the failure detail already captured.
    • B. The X-Ray status field only records a numeric response status; X-Ray does not capture the Python stack trace text unless the application explicitly adds it as metadata, so this does not deliver the exception detail.
    • C. Redeploying and waiting for a natural recurrence is slower and unnecessary, since the exception and stack trace for the failures that already occurred are already sitting in the existing CloudWatch Logs.
    • D. The Monitoring tab's error count graph only shows the number of errors over time; it does not display the exception message text or stack trace for individual invocations.

    Subdomain 4.1: Assist in a root cause analysis

    29.Messages published to an SNS topic are supposed to fan out to an HTTPS endpoint and an SQS queue, but some deliveries to the HTTPS endpoint appear to silently fail. Which TWO actions help the team diagnose exactly why those deliveries are failing?(Select 2)

    1. A.Enable delivery status logging for the SNS topic and configure the IAM roles, so SNS writes per-attempt delivery outcomes, including HTTP response codes, to CloudWatch Logs.
    2. B.Configure a redrive policy with a dead-letter queue on the topic's HTTPS subscription, so messages that exhaust SNS's retry attempts land in the DLQ for inspection instead of being dropped.
    3. C.Switch the HTTPS subscription to an SQS subscription entirely, since SNS delivery status logging is only available for queue-based subscriptions, never for HTTPS endpoints.
    4. D.Enable CloudTrail data events for the SNS topic, since CloudTrail is assumed to record the HTTP response body returned by every subscriber endpoint on each publish.
    5. E.Increase the SNS topic's message retention period, since longer retention is assumed to cause SNS to keep retrying HTTPS deliveries indefinitely until they succeed.
    6. F.Add a resource policy statement granting `sns:Publish` to the HTTPS endpoint's IAM role, since missing publish permissions are the only reason HTTPS deliveries can fail silently.
    Show answer & explanation

    Correct answers: A, B — Enable delivery status logging for the SNS topic and configure the IAM roles, so SNS writes per-attempt delivery outcomes, including HTTP response codes, to CloudWatch Logs.; Configure a redrive policy with a dead-letter queue on the topic's HTTPS subscription, so messages that exhaust SNS's retry attempts land in the DLQ for inspection instead of being dropped.

    • A. SNS delivery status logging records the outcome of each delivery attempt, including the HTTP response code returned by the endpoint, giving the team the per-attempt diagnostic detail needed to see why deliveries are failing.
    • B. A subscription-level dead-letter queue captures the messages SNS could not deliver after exhausting its retry policy, letting the team inspect exactly which messages failed and their content.
    • C. SNS delivery status logging works for HTTPS subscriptions as well as queue-based ones, so switching away from the HTTPS endpoint is unnecessary and does not match how the feature actually works.
    • D. CloudTrail data events record that a publish API call occurred and its parameters; they do not capture the HTTP response returned by a subscriber endpoint, so this does not reveal the delivery failure reason.
    • E. The topic's message retention setting does not exist as a retry-extension control for SNS deliveries; SNS retries follow its own fixed and configurable backoff policy independent of any retention setting.
    • F. A missing `sns:Publish` permission would prevent the publisher from sending to the topic at all, which is unrelated to the topic delivering a message onward to a subscribed HTTPS endpoint, and it is not the only possible cause of a silent delivery failure.

    Subdomain 4.2: Instrument code for observability

    30.A company's operations team wants to be notified in a Slack channel within a minute whenever a Lambda function's `Throttles` metric exceeds zero, indicating the function is hitting its concurrency limit. Which two components must be combined to implement this notification with the least custom code? (Select TWO.)(Select 2)

    1. A.A CloudWatch alarm on the `Throttles` metric that transitions to the ALARM state as soon as the metric value exceeds zero.
    2. B.An SNS topic that the alarm publishes to, with an AWS Chatbot integration subscribed and configured for the target Slack channel.
    3. C.A scheduled Lambda function that polls `GetMetricData` every minute and posts to Slack using a custom webhook client built from scratch.
    4. D.A CloudTrail Lake query that runs hourly against data events to detect throttling patterns in the historical event log.
    5. E.The function's dead-letter queue, configured to forward failed invocation records directly to a Slack-hosted API endpoint.
    Show answer & explanation

    Correct answers: A, B — A CloudWatch alarm on the `Throttles` metric that transitions to the ALARM state as soon as the metric value exceeds zero.; An SNS topic that the alarm publishes to, with an AWS Chatbot integration subscribed and configured for the target Slack channel.

    • A. An alarm evaluating the Throttles metric against a zero threshold is what actually detects the condition and changes state the moment throttling occurs.
    • B. An SNS topic with a Chatbot integration subscribed is the managed delivery path that turns the alarm state change into an actual Slack message, with no custom webhook code to maintain.
    • C. A custom scheduled poller reinvents alarm evaluation and webhook delivery that CloudWatch alarms and Chatbot already provide, adding unnecessary code to build and maintain.
    • D. CloudTrail records management and data-plane API calls on an hourly cadence at best, which is far too coarse for a within-a-minute notification requirement.
    • E. A dead-letter queue captures failed asynchronous invocation payloads for later reprocessing; it has no built-in mechanism to post directly to an external Slack endpoint.

    Subdomain 4.2: Instrument code for observability

    31.An application running on Amazon ECS behind an Application Load Balancer intermittently receives traffic routed to tasks that have not finished initializing their database connection pool, causing request failures right after deployment. Which configuration change best prevents traffic from reaching a task before it is actually ready to serve requests?

    1. A.Define an ALB target group health check against a `/health` endpoint that only returns success once the task's database connection pool has finished initializing.
    2. B.Increase the ECS service's `minimumHealthyPercent` to 100 so that no existing tasks are stopped until every new task has started running.
    3. C.Add a fixed 30-second `sleep` at the start of the container's entrypoint script before the application process starts listening on its port.
    4. D.Configure Amazon CloudWatch Container Insights to alert the on-call engineer whenever a task's CPU utilization spikes above 80 percent after deployment.
    Show answer & explanation

    Correct answer: A — Define an ALB target group health check against a `/health` endpoint that only returns success once the task's database connection pool has finished initializing.

    • A. A health check endpoint that reports ready only after the connection pool is initialized lets the ALB target group hold traffic back from a task until it can genuinely serve requests, which directly addresses a readiness gap rather than just an existence check.
    • B. Controlling how many existing tasks stay running during deployment does not change whether the ALB considers a brand-new task ready before its dependencies finish initializing.
    • C. A fixed sleep delays startup by a guessed duration regardless of actual readiness, so it can still route traffic too early on a slow start or waste time on a fast one.
    • D. Alerting on CPU utilization after the fact notifies engineers of a symptom but does nothing to stop the load balancer from routing requests to an unready task in the first place.

    Subdomain 4.2: Instrument code for observability

    32.A developer wants to emit a custom CloudWatch metric named `CacheHitRatio` from a containerized application running on Amazon ECS, using the CloudWatch agent rather than making direct API calls from application code. Which two configuration facts about this approach are correct? (Select TWO.)(Select 2)

    1. A.The CloudWatch agent can be configured to scan structured log output for embedded metric format entries and forward the extracted metrics to CloudWatch.
    2. B.Emitting metrics through embedded metric format via the agent only requires the `logs:PutLogEvents` permission, not the `cloudwatch:PutMetricData` permission.
    3. C.The CloudWatch agent requires the application to open a raw TCP socket directly to the agent process on every metric emission for data to be accepted.
    4. D.Using the CloudWatch agent for embedded metric format removes the need for the container to hold any IAM permissions related to logging or metrics at all.
    5. E.The CloudWatch agent can only forward metrics emitted using the older `PutMetricData` low-level XML request format, never embedded metric format JSON.
    Show answer & explanation

    Correct answers: A, B — The CloudWatch agent can be configured to scan structured log output for embedded metric format entries and forward the extracted metrics to CloudWatch.; Emitting metrics through embedded metric format via the agent only requires the `logs:PutLogEvents` permission, not the `cloudwatch:PutMetricData` permission.

    • A. The CloudWatch agent supports reading embedded metric format log output and forwarding the extracted metrics to CloudWatch, which is the documented mechanism for generating custom metrics without direct PutMetricData calls.
    • B. Embedded metric format only requires the `logs:PutLogEvents` permission to ship the structured log entries; CloudWatch extracts the metric from the log content, so `cloudwatch:PutMetricData` is not needed.
    • C. Applications write embedded metric format entries as standard structured log output, not by opening a dedicated raw TCP socket to the agent process for each metric.
    • D. The task still needs `logs:PutLogEvents` permission to write the log entries the agent processes; embedded metric format removes the need for PutMetricData specifically, not all logging or metrics permissions.
    • E. Embedded metric format is itself a JSON-based log structure, and it is the format the agent is designed to parse; it is not limited to forwarding legacy XML-based PutMetricData requests.

    Subdomain 4.3: Optimize applications by using AWS services and features

    33.A mobile app calls a Lambda-backed API that must respond within double-digit millisecond latency for every request, including the first request after a period of inactivity. Standard cold starts are causing occasional multi-second response times that fail the app's latency requirement. Which configuration change directly addresses this?

    1. A.Configure provisioned concurrency on the function so a set number of execution environments stay pre-initialized and ready to respond immediately.
    2. B.Set reserved concurrency on the function to a high value so more concurrent executions are permitted during traffic bursts.
    3. C.Increase the function's timeout setting so slow cold starts are given more time to complete before the client receives an error.
    4. D.Attach an SNS subscription filter policy to the function's trigger so only high-priority requests reach the function during peak load.
    Show answer & explanation

    Correct answer: A — Configure provisioned concurrency on the function so a set number of execution environments stay pre-initialized and ready to respond immediately.

    • A. Provisioned concurrency keeps a specified number of execution environments initialized and ready in advance, which is exactly what eliminates cold-start latency for interactive, latency-sensitive workloads like this one.
    • B. Reserved concurrency sets a ceiling and floor on how many concurrent invocations are allowed, but it does not pre-initialize environments, so the first invocation into a new environment still incurs a cold start.
    • C. A longer timeout lets a slow invocation run longer without erroring, but it does nothing to shorten the cold-start delay itself, so the double-digit millisecond requirement would still be missed.
    • D. Filter policies control which messages reach a subscriber based on attributes or body content; they do not affect how quickly an execution environment initializes.

    Subdomain 4.3: Optimize applications by using AWS services and features

    34.A Lambda function connects to an external HTTPS API and a relational database on every invocation, and the team notices high average duration under load. Which changes would reduce resource usage and duration without altering the function's business logic? (Select TWO.)(Select 2)

    1. A.Move the HTTPS client and database connection objects to global scope so they are created once and reused across invocations in a warm execution environment.
    2. B.Use a connection pooling mechanism, such as RDS Proxy, so database connections are reused across invocations instead of opening a new connection every time.
    3. C.Increase the function's reserved concurrency limit, since higher reserved concurrency directly reduces the CPU time each individual invocation consumes.
    4. D.Wrap every external API call in a broad `try/except` block that silently swallows all exceptions, since fewer raised errors means the runtime executes faster.
    5. E.Reduce the function's memory allocation to the platform minimum, since lower memory settings always shorten execution duration for network-bound code.
    Show answer & explanation

    Correct answers: A, B — Move the HTTPS client and database connection objects to global scope so they are created once and reused across invocations in a warm execution environment.; Use a connection pooling mechanism, such as RDS Proxy, so database connections are reused across invocations instead of opening a new connection every time.

    • A. Declaring HTTP and database clients outside the handler, in global scope, lets a warm execution environment reuse the already-established client across multiple invocations instead of paying setup cost every time.
    • B. RDS Proxy pools and reuses database connections across Lambda invocations, avoiding the overhead of establishing a new connection on every call and reducing both duration and load on the database.
    • C. Reserved concurrency governs how many concurrent invocations are permitted; it does not change the CPU time or duration of any single invocation's work.
    • D. Swallowing exceptions hides failures rather than reducing work performed; it does not shorten the time spent making the external API call and can mask real production issues.
    • E. Lambda allocates CPU proportionally to memory, so minimizing memory can slow down CPU-sensitive or network-serialization work rather than universally shortening duration.

    Subdomain 4.3: Optimize applications by using AWS services and features

    35.A web application repeatedly queries a relational database for the same product catalog data on nearly every page load, and the database is showing high read load during peak hours. The team wants to add an application-level cache in front of the database to serve these repeated reads without querying the database each time. Which AWS service is designed for this use case?

    1. A.Amazon ElastiCache, used as an in-memory cache that the application checks before falling back to the relational database on a cache miss.
    2. B.AWS Secrets Manager, used to store the catalog data as a versioned secret that the application retrieves on each page load.
    3. C.Amazon EventBridge, used to schedule a recurring rule that periodically re-runs the catalog query and discards the results.
    4. D.AWS CloudTrail, used to record each database query as an event so the application can replay results from the trail instead of the database.
    Show answer & explanation

    Correct answer: A — Amazon ElastiCache, used as an in-memory cache that the application checks before falling back to the relational database on a cache miss.

    • A. ElastiCache provides an in-memory data store that applications check first and populate on a miss, which is the standard pattern for offloading repeated reads of the same data away from a relational database.
    • B. Secrets Manager is designed to store and rotate credentials and other sensitive secrets; it enforces size and access patterns unsuited to serving general application read-through caching of catalog data.
    • C. EventBridge schedules and routes events; it has no built-in storage layer for serving cached query results back to the application on demand.
    • D. CloudTrail records API calls for auditing and governance; it does not capture or replay application-level database query results.

    Want the full experience?

    These are just samples. Practice the full AWS Certified Developer - Associate (DVA-C02) question bank in quiz mode — free, no signup, with domain practice and exam simulation.