DVA-C02 — Frequently Asked Questions
Community-vetted answers to 30 common questions about this exam.
To log every Lambda invocation to an SQS queue, you should configure the Lambda function's destination for both success and failure. In the function's configuration, you can set an SQS queue as the destination for 'On success' and 'On failure'. This ensures that a record of every invocation, regardless of its outcome, is sent to the queue without modifying the function's code.
The most effective method is to use weighted aliases in AWS Lambda. You would publish a new version of the Lambda function and then configure the alias used by API Gateway to route a small percentage of traffic (e.g., 5%) to the new version and the remaining traffic (95%) to the stable version. This allows for canary testing or blue/green deployments with minimal risk.
You should never expose a third-party API key directly in a browser-based SPA. The secure pattern is to create a backend API, such as an AWS Lambda function fronted by Amazon API Gateway. The SPA calls your API Gateway endpoint, and the Lambda function, which securely stores the third-party API key in its environment variables (encrypted with AWS KMS) or in AWS Secrets Manager, makes the call to the external service and returns the result to the SPA.
The best solution is to use AWS Secrets Manager. You can store the API key as a secret in Secrets Manager and configure it for automatic rotation. Secrets Manager can use a built-in Lambda function to rotate secrets for many AWS services, or you can provide a custom Lambda function for third-party API keys. This automates the entire rotation process without requiring changes to your application code.
To prevent CloudFormation from overwriting an SSM Parameter Store value, you should reference the parameter in your CloudFormation template using a dynamic reference, such as {{resolve:ssm:parameter-name}}. Dynamic references are resolved at runtime, and CloudFormation does not store the value in the stack, thus it will not attempt to update or reset it during a stack update.
To manage costs and data volume, you should create custom sampling rules in the AWS X-Ray console. You can define rules to sample a specific percentage of requests or a fixed number of requests per second. For example, you might sample 10% of all requests but ensure that any request resulting in an error is always sampled (100%). This provides a good balance between observability and cost.
For dependencies that are too large for a Lambda deployment package, you should use Lambda Layers or Amazon Elastic File System (EFS). For a very large library like 15 GB, mounting an EFS file system to the Lambda function is the most suitable option. You can store the library on the EFS volume, and the Lambda function can access it directly at runtime, bypassing the deployment package size limits.
The two primary commands are sam build and sam deploy. The sam build command prepares your application by downloading dependencies and compiling code. The sam deploy command packages your code, uploads it to Amazon S3, and then uses AWS CloudFormation to deploy the application based on the SAM template.
You can use Amazon EventBridge to monitor certificate expiration events from AWS Certificate Manager. Create an EventBridge rule that listens for the ACM Certificate Expiration event. Configure the rule to trigger a target, such as an Amazon SNS topic, which can then send an email or SMS notification to your team a specified number of days before the certificate expires.
For large files, you should use envelope encryption. First, call the GenerateDataKey API in AWS KMS. This returns a plaintext data key and an encrypted copy of that data key. Use the plaintext data key locally to encrypt your large file. Once the file is encrypted, you can discard the plaintext data key and store the encrypted file along with the encrypted data key. To decrypt, you would use the Decrypt API to retrieve the plaintext data key.
You should use IAM database authentication. This feature allows you to authenticate to your RDS database using an IAM user or role. Your application generates an authentication token using the AWS SDK, which is then used to connect to the database instead of a password. This token is temporary and eliminates the need to store long-term credentials in your application.
You need to configure cross-account access by updating the resource-based policy on the Kinesis data stream. Add a statement to the stream's policy that grants the necessary permissions (e.g., kinesis:GetRecords) to the IAM role attached to the EC2 instance in the other account. The EC2 instance's role must also have a trust policy that allows it to be assumed.
Use Amazon EventBridge to create a rule that listens for CloudFormation stack events. You can filter for events where the StackName matches your specific environment and the event detail type is CloudFormation Stack Status Change. Set the target of this rule to an Amazon SNS topic subscribed by the QA team's email addresses to send them an automatic notification.
You can configure canary settings on an API Gateway stage. When you deploy your API, you can enable canary deployment and specify the percentage of traffic to send to the canary version (which points to a new Lambda alias/version). This allows you to test the new version with a small percentage of live traffic before a full rollout.
You should enable automatic rotation for the secret in AWS Secrets Manager. When you configure rotation, Secrets Manager uses a Lambda function to create a new password, updates the RDS database with the new password, and then updates the secret value. This process is designed to be seamless and can be configured to ensure the application can always connect, achieving zero-downtime rotation.
The most cost-effective way is to use AWS Lambda Power Tuning in combination with Amazon CloudWatch Logs Insights. You can run a CloudWatch Logs Insights query across all your log groups to find Lambda invocations where the @duration field exceeds a certain threshold. This allows you to identify slow functions without incurring the cost of tracing every single request with AWS X-Ray.
To handle duplicate messages, your Lambda function's processing logic must be idempotent. This means that processing the same message multiple times should have the same effect as processing it once. You can achieve this by using a unique ID from the message (like MessageId) to track whether the message has already been successfully processed, for example, by storing the ID in a DynamoDB table with a conditional write.
The best practice is to use an Origin Access Control (OAC). You configure the CloudFront distribution with an OAC, which creates a special CloudFront identity. Then, you update the S3 bucket policy to explicitly deny all access except for requests coming from that specific CloudFront OAC. This ensures that objects in the S3 bucket can only be accessed via the CloudFront URL.
The most cost-effective and simplest method is to use an Amazon EventBridge (formerly CloudWatch Events) rule. You can create a rule with a cron expression (e.g., cron(0 12 ? *) for 12:00 PM UTC daily) and set the Lambda function as the target. This is a managed service with no additional cost for the scheduling itself, and you only pay for the Lambda execution.
You should use AWS Secrets Manager or AWS Systems Manager (SSM) Parameter Store. For credentials that require automatic rotation, Secrets Manager is the best choice. For static configuration values, SSM Parameter Store is suitable. In both cases, you can store the credentials securely and reference them in your Lambda function's environment variables or retrieve them at runtime using the AWS SDK. Lambda automatically encrypts environment variables at rest using AWS KMS.
You can limit the concurrency in two ways. First, you can set a reserved concurrency limit directly on the Lambda function, which caps the total number of concurrent executions. Second, and more specifically for SQS, you can configure the event source mapping to limit the BatchSize and the MaximumConcurrency. This controls how many messages are processed in parallel from the queue.
The most cost-effective solution is to store the video files in an Amazon S3 bucket. Your application should upload the video to S3 and then send a message to the SQS queue containing only the S3 object key (and bucket name). The worker application that processes the message can then use the key to retrieve the video file directly from S3. This avoids the 256 KB message size limit of SQS and is highly cost-effective for storage.
The most effective way to optimize CodeBuild performance is to enable caching. You can configure CodeBuild to cache dependencies (like Maven or npm packages) in an S3 bucket. On subsequent builds, CodeBuild will pull the cached dependencies instead of downloading them again, significantly reducing build time. You can also choose a more powerful compute type for the build environment.
You can use a dynamic reference in your CloudFormation template. The syntax is {{resolve:ssm:parameter-name}}. This tells CloudFormation to fetch the latest version of the specified parameter from SSM Parameter Store at runtime. This is a secure way to inject configuration values without hardcoding them in the template.
You can use API Gateway's Mock Integration. This allows you to configure an API method to return a static, predefined response without integrating with any backend service like Lambda. You can define the HTTP status code, response headers, and a JSON body template. This is ideal for allowing frontend developers to work against a simulated API before the actual backend is ready.
You should use the Retry and Catch fields within the state definition in your Amazon States Language (ASL) file. The Retry field allows you to specify which error types (e.g., Lambda.ServiceException) should trigger a retry, along with parameters like MaxAttempts, IntervalSeconds, and a BackoffRate. The Catch field can be used to handle errors that are not retried, directing the execution to a fallback state.
You should configure a dead-letter queue (DLQ) for the Lambda function. You can specify either an Amazon SQS queue or an Amazon SNS topic as the DLQ. When an asynchronous invocation fails after all retries are exhausted, Lambda automatically sends the event payload to the configured DLQ. This is a fully managed solution that requires no custom code to handle the failed events.
You can use AWS Config to monitor for this. Create an AWS Config rule, such as iam-role-managed-policy-check, or a custom rule that evaluates IAM roles. Configure the rule to trigger on configuration changes. Then, set up an Amazon EventBridge rule to listen for 'Compliance Change' events from AWS Config. When a non-compliant resource (a role not created by CloudFormation) is detected, the EventBridge rule can trigger an Amazon SNS notification.
You can use an intrinsic function in the CloudFormation template. In the Environment property of your AWS::Lambda::Function resource, you can set the environment variable's value using the !GetAtt intrinsic function to retrieve the Arn of the AWS::Logs::LogGroup resource. For example: LOG_GROUP_NAME: !GetAtt MyLogGroup.Arn.
To ensure all services appear on the X-Ray service map, you must instrument each service with the AWS X-Ray SDK. The SDK captures data about incoming and outgoing requests and propagates the trace header. For AWS services like Lambda, API Gateway, and DynamoDB, you can often enable active tracing without code changes. For services running on EC2 or containers, you must install the X-Ray daemon and use the SDK to instrument your application code.
Ready to practice?
Access 100 DVA-C02 questions with instant feedback and detailed explanations.
View DVA-C02 Practice Questions →← Back to DVA-C02 AWS Certified Developer - Associate Study Guide