DVA-C02 Practice Exam: AWS Certified Developer - Associate
Lambda, DynamoDB, APIs, SDKs — write code against AWS without footgunning yourself.
What you'll be tested on
- Development with AWS Services
- Security
- Deployment
- Troubleshooting and Optimization
Sample DVA-C02 questions
A company is implementing an application on Amazon EC2 instances. The application needs to process incoming transactions. When the application detects a transaction that is not valid, the application must send a chat message to the company's support team. To send the message, the application needs to retrieve the access token to authenticate by using the chat API. A developer needs to implement a solution to store the access token. The access token must be encrypted at rest and in transit. The access token must also be accessible from other AWS accounts. Which solution will meet these requirements with the LEAST management overhead?
- Use an AWS Systems Manager Parameter Store SecureString parameter that uses an AWS Key Management Service (AWS KMS) AWS managed key to store the access token. Add a resource-based policy to the parameter to allow access from other accounts. Update the IAM role of the EC2 instances with permissions to access Parameter Store. Retrieve the token from Parameter Store with the decrypt flag enabled. Use the decrypted access token to send the message to the chat.
- Encrypt the access token by using an AWS Key Management Service (AWS KMS) customer managed key. Store the access token in an Amazon DynamoDB table. Update the IAM role of the EC2 instances with permissions to access DynamoDB and AWS KMS. Retrieve the token from DynamoDDecrypt the token by using AWS KMS on the EC2 instances. Use the decrypted access token to send the message to the chat.
- Use AWS Secrets Manager with an AWS Key Management Service (AWS KMS) customer managed key to store the access token. Add a resource-based policy to the secret to allow access from other accounts. Update the IAM role of the EC2 instances with permissions to access Secrets Manager. Retrieve the token from Secrets Manager. Use the decrypted access token to send the message to the chat.
- Encrypt the access token by using an AWS Key Management Service (AWS KMS) AWS managed key. Store the access token in an Amazon S3 bucket. Add a bucket policy to the S3 bucket to allow access from other accounts. Update the IAM role of the EC2 instances with permissions to access Amazon S3 and AWS KMS. Retrieve the token from the S3 bucket. Decrypt the token by using AWS KMS on the EC2 instances. Use the decrypted access token to send the massage to the chat.
Show answer
C — Use AWS Secrets Manager with an AWS Key Management Service (AWS KMS) customer managed key to store the access token. Add a resource-based policy to the secret to allow access from other accounts. Update the IAM role of the EC2 instances with permissions to access Secrets Manager. Retrieve the token from Secrets Manager. Use the decrypted access token to send the message to the chat.AWS Secrets Manager is purpose-built for secrets like access tokens, encrypts them at rest with a KMS customer managed key, and supports resource-based policies on secrets, which is required for granting access from other AWS accounts. A customer managed key is needed because you cannot share secrets encrypted with AWS managed keys cross-account. Option A fails because Parameter Store parameters do not support resource-based policies for cross-account access. Options B and D involve manual encryption and storage in DynamoDB or S3, adding management overhead and complexity instead of using a managed secret store.
A company is running Amazon EC2 instances in multiple AWS accounts. A developer needs to implement an application that collects all the lifecycle events of the EC2 instances. The application needs to store the lifecycle events in a single Amazon Simple Queue Service (Amazon SQS) queue in the company's main AWS account for further processing. Which solution will meet these requirements?
- Configure Amazon EC2 to deliver the EC2 instance lifecycle events from all accounts to the Amazon EventBridge event bus of the main account. Add an EventBridge rule to the event bus of the main account that matches all EC2 instance lifecycle events. Add the SQS queue as a target of the rule.
- Use the resource policies of the SQS queue in the main account to give each account permissions to write to that SQS queue. Add to the Amazon EventBridge event bus of each account an EventBridge rule that matches all EC2 instance lifecycle events. Add the SQS queue in the main account as a target of the rule.
- Write an AWS Lambda function that scans through all EC2 instances in the company accounts to detect EC2 instance lifecycle changes. Configure the Lambda function to write a notification message to the SQS queue in the main account if the function detects an EC2 instance lifecycle change. Add an Amazon EventBridge scheduled rule that invokes the Lambda function every minute.
- Configure the permissions on the main account event bus to receive events from all accounts. Create an Amazon EventBridge rule in each account to send all the EC2 instance lifecycle events to the main account event bus. Add an EventBridge rule to the main account event bus that matches all EC2 instance lifecycle events. Set the SQS queue as a target for the rule.
Show answer
D — Configure the permissions on the main account event bus to receive events from all accounts. Create an Amazon EventBridge rule in each account to send all the EC2 instance lifecycle events to the main account event bus. Add an EventBridge rule to the main account event bus that matches all EC2 instance lifecycle events. Set the SQS queue as a target for the rule.EventBridge supports cross-account event buses: you grant the other accounts permission to send events to the main account's event bus, create rules in each account that route EC2 lifecycle events to that bus, and then a rule on the main bus targets the SQS queue. This is the managed, event-driven design. Option A is wrong because EC2 events cannot be delivered directly across accounts without a rule in each account. Option B is insufficient because an EventBridge rule in one account cannot directly target a queue in another account without the event bus routing. Option C replaces native events with polling, which is inefficient.
An application is using Amazon Cognito user pools and identity pools for secure access. A developer wants to integrate the user-specific file upload and download features in the application with Amazon S3. The developer must ensure that the files are saved and retrieved in a secure manner and that users can access only their own files. The file sizes range from 3 KB to 300 MB. Which option will meet these requirements with the HIGHEST level of security?
- Use S3 Event Notifications to validate the file upload and download requests and update the user interface (UI).
- Save the details of the uploaded files in a separate Amazon DynamoDB table. Filter the list of files in the user interface (UI) by comparing the current user ID with the user ID associated with the file in the table.
- Use Amazon API Gateway and an AWS Lambda function to upload and download files. Validate each request in the Lambda function before performing the requested operation.
- Use an IAM policy within the Amazon Cognito identity prefix to restrict users to use their own folders in Amazon S3.
Show answer
D — Use an IAM policy within the Amazon Cognito identity prefix to restrict users to use their own folders in Amazon S3.Amazon Cognito identity pools let you map the authenticated user's identity into IAM policy variables such as ${cognito-identity.amazonaws.com:sub}, so you can scope S3 permissions to a user-specific folder prefix. This gives each user secure access to only their own files with no custom code. S3 event notifications (A) react to uploads but cannot enforce per-user authorization. A DynamoDB filtering table (B) adds complexity without enforcing S3-level security. Routing all file transfers through API Gateway and Lambda (C) adds latency, cost, and payload size limits compared with direct S3 access.
Access plans
| Access | Price |
|---|---|
| 3 months | |
| 1 year | |
| Lifetime |
Free preview inside — try 5 questions before you pay anything.
FAQ
How many practice questions are in this DVA-C02 bank?
556 questions covering the current DVA-C02 AWS Certified Developer - Associate syllabus, every one with the correct answer and an explanation.How long is the real DVA-C02 exam?
The official DVA-C02 exam gives you 130 minutes. Our timed exam mode uses the same limit so the pace feels familiar.What does DVA-C02 access cost?
Plans start at $3.99 for 3 months. One payment, no subscription — and far cheaper than retaking the real exam.