How to automate S3 object tagging after delayed third-party content audit?

A photo sharing application uses Amazon S3 to store image files. All user images are manually audited for inappropriate content by a third-party company. The audits are completed 1-24 hours after user upload and the results are written to an Amazon DynamoDB table, which uses the S3 object key as a primary key. The database items can be queried by using a REST API created by the third-party company. An application developer needs to implement an automated process to tag all S3 objects with the results of the content audit. What should the developer do to meet these requirements in the MOST operationally efficient way?

  1. Create an AWS Lambda function to run in response to the s3:ObjectCreated event type. Write the S3 key to an Amazon Simple Queue Service (Amazon SQS) queue with a visibility timeout of 24 hours. Create and configure a second Lambda function to read items from the queue. Retrieve the results for each item from the DynamoDB table. Tag each S3 object accordingly.
  2. Create an AWS Lambda function to run in response to the s3:ObjectCreated event type. Integrate the function into an AWS Step Functions standard workflow. Define an AWS Step Functions Wait state and set the value to 24 hours. Create and configure a second Lambda function to retrieve the audit results and tag the S3 objects accordingly after the Wait state is over. Source Reference Answer
  3. Create an AWS Lambda function to load all untagged S3 objects. Retrieve the results for each item from the REST API and tag each S3 object accordingly. Create and configure an Amazon EventBridge rule to run at regular intervals. Set the Lambda function as a target for the EventBridge rule.
  4. Launch an Amazon EC2 instance. Deploy a script to the EC2 instance to use the external database results to tag the S3 objects accordingly. Configure a crontab file to run the script at regular intervals.

Community Votes

B
57%
C
43%

57% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the ability to decouple an asynchronous, long-running external process from an S3 upload event using AWS Step Functions, specifically leveraging a Wait state to handle the 1–24 hour audit delay without polling or managing infrastructure.

This DVA-C02 question tests how to orchestrate a delayed, event-driven workflow using AWS Step Functions to tag S3 objects after a third-party audit. Community debate centers on whether a scheduled Lambda (Option C) or a Step Functions Wait state (Option B) is the most operationally efficient approach.

Many candidates choose Option C (EventBridge + scheduled Lambda) because it appears simpler and avoids a 24-hour wait, but it fails to efficiently tie the tagging action to the specific S3 object upload event and results in repeated, wasteful API calls to the REST API for objects not yet audited.

Community Discussion (15 comments)

AssessmentKing 👍 7 Selected: B
Images are first uploaded to S3 bucket. Then, manual audit is performed that lasts 1-24 hours. Only after the audit of the image is finished we can run our Lambda function. If we run event at regular intervals (what does it mean?) should we run it every hour and then we would have bunch of untagged objects that haven't been audited and we would add a tag to them which doesn't make sense. - In option B they explicitly mention that the Wait period will be 24 hours thus insuring that the audit of those objects has been completed. Only then we run the Lambda function.
mooncake1 👍 1 Selected: B
C will take too long... Each img will takd 24 hrs, and it will wait for all imgs. I do not understand why people are confused.. It needs to be triggered when the img is uploaded.
Arad 👍 1 Selected: C
C is the right answer. Lambda+EvenBridge is operationally more efficient than Step Function.
ShakthiGCP 👍 1 Selected: B
Ans: B . We have to wait for 1- 24 hrs .we cant just run the lambda functions to get untagged objects .
Saudis 👍 1 Selected: C
I am confuse because the chatGPT Says C
devmo 👍 1 Selected: C
With option B, what if the external company doesn't complete the audit in 24 hours Least operational over head and long term solution would be going with 1 lambda and event bridge is what I feel.
MasoudK 👍 3
C coz of operationally efficient words
tsangckl 👍 2 Selected: C
This solution leverages AWS Lambda, which is a serverless compute service that runs your code in response to events and automatically manages the underlying compute resources for you1. By using Lambda in conjunction with Amazon EventBridge, which can trigger events at regular intervals, you can create a system that periodically checks for new audit results and applies tags to S3 objects without the need for managing server instances or handling queue visibility timeouts. This approach is not only operationally efficient but also cost-effective, as you pay only for the compute time you consume with Lambda21.
65703c1 👍 2 Selected: B
B is the correct answer.
DeaconStJohn 👍 4 Selected: B
I'm still not sure if B is correct. However, I think this use case is very similar to a feature that exists in step functions. Although the wording doesn't answer the question directly and I think waiting 24 hours is the opposite of operationally efficient. The GetTaskToken feature that is part of service integration in step functions would be a perfect match for this scenario, removing the 24 hour wait while maintaining operational efficiency using AWS Step functions. I can only hope this is what they are getting at when I answer this on the exam. https://docs.aws.amazon.com/step-functions/latest/dg/connect-to-resource.html
KarBiswa 👍 2 Selected: C
Best option considering the question conditions. Reading from Rest API
SerialiDr 👍 4 Selected: C
C. Create an AWS Lambda function to load all untagged S3 objects. Retrieve the results for each item from the REST API and tag each S3 object accordingly. Create and configure an Amazon EventBridge rule to run at regular intervals. Set the Lambda function as a target for the EventBridge rule. This solution leverages AWS Lambda for processing and tagging S3 objects based on the audit results available through the REST API. By using Amazon EventBridge to trigger the Lambda function at regular intervals, the developer ensures that the process runs automatically without manual intervention, efficiently handling the tagging of S3 objects once the audit results are available. This approach minimizes operational effort and does not require the continuous monitoring of S3 object creation or the management of complex workflows.
monishvster 👍 1 Selected: A
Should be A
Jisking 👍 3 Selected: B
I may choose B.
CrescentShared 👍 3 Selected: C
A does not make any sense.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Understanding the Scenario

The workflow involves three distinct phases:

1. S3 Upload – A user uploads an image. 2. External Audit – A third-party company audits the image, taking 1–24 hours. 3. Tagging – After the audit, the S3 object must be tagged with the result.

The key constraint is the asynchronous, long-running external process. The system must wait for the audit to complete before tagging.

Why Option B is Correct

Option B uses an AWS Lambda function triggered by the s3:ObjectCreated event, which then starts an AWS Step Functions standard workflow. The workflow includes a Wait state set to 24 hours, after which a second Lambda retrieves the audit result from the REST API and tags the S3 object.

This is the most operationally efficient solution because:

  • Event-driven: Tagging is tied directly to the upload event, not a blind schedule.
  • No infrastructure management: Step Functions and Lambda are fully managed serverless services.
  • Precise orchestration: The Wait state cleanly handles the 1–24 hour delay without polling or maintaining state in a database.
  • Scalable: Each upload spawns its own workflow instance, avoiding batch-processing bottlenecks.
As community member DeaconStJohn noted, while the 24-hour Wait state may seem inefficient, Step Functions is designed exactly for this kind of long-running orchestration, and it avoids the complexity of alternatives like SQS visibility timeouts or polling.

Why the Other Options are Wrong

  • Option A (SQS with 24-hour visibility timeout): SQS visibility timeouts are not designed for precise, long delays. A message would become visible again after 24 hours, but if the audit takes less than 24 hours, the system still waits the full timeout. If it takes longer, the message reappears prematurely. This is a misuse of SQS.
  • Option C (EventBridge scheduled Lambda): While serverless, this approach polls the REST API at regular intervals for all untagged objects. This is inefficient because:
- It makes unnecessary API calls for objects not yet audited. - It introduces latency (up to the schedule interval) before tagging. - It does not scale well with a large number of objects.
  • Option D (EC2 + crontab): This requires managing an EC2 instance, deploying scripts, and maintaining a crontab. It is the least operationally efficient option due to the operational overhead of infrastructure management, patching, and scaling.

Community Insight

The debate between B and C highlights a common confusion: event-driven orchestration vs. scheduled polling. While C seems simpler, it violates the principle of operational efficiency by introducing unnecessary API calls and latency. Step Functions (Option B) is purpose-built for this exact scenario.

Official Reference

Exam Strategy

When a question emphasizes 'operationally efficient' and involves a long-running, asynchronous external process, look for serverless orchestration tools like AWS Step Functions. Avoid solutions that require managing infrastructure (EC2) or polling (scheduled Lambda) unless the scenario explicitly calls for batch processing.

Related Analysis

Practice All DVA-C02 Questions

Access 100 questions with complete answers and detailed explanations.

View Full DVA-C02 Practice Test →

← Back to DVA-C02 Study Guide