Validates proficiency in developing, deploying, and debugging AWS-based applications. Covers CI/CD and serverless architectures.
AWS Lambda, Amazon API Gateway, Amazon DynamoDB, Amazon S3 SDK, Amazon SQS & SNS
AWS IAM, AWS KMS, Amazon Cognito, AWS Secrets Manager, STS Tokens
AWS CodePipeline, AWS CodeDeploy, AWS Elastic Beanstalk, AWS SAM, AWS CDK
Amazon CloudWatch, AWS X-Ray, Amazon EventBridge, AWS Step Functions, Performance Optimization
Try real exam-style questions from the free sample set. Each answer comes with a full explanation.
A streaming data processing team operates an application that consumes data from Amazon Kinesis Data Streams using KCL (Kinesis Client Library). The stream currently has 8 shards, and they want to increase the number of KCL worker instances to maximize processing performance.
What is the maximum number of KCL worker instances that can be deployed to improve processing performance?
Answer: D. 8
A team is processing data from Kinesis Data Streams with KCL and wants to maximize performance by increasing the number of workers. The core principle of KCL is '1 shard = maximum 1 worker.' With 8 shards, 8 workers each exclusively handle one shard to maximize processing performance, and from the 9th worker onward, there are no shards to assign and they remain idle. Therefore, the maximum number of effective KCL workers that can be deployed to improve performance equals the number of shards: 8.
KCL (Kinesis Client Library) uses a DynamoDB lease table to dynamically manage the mapping between each shard and worker. When a new worker starts, it checks the lease table for available shards and acquires ownership. KCL automates complex consumer management, including automatically redistributing leases on worker failure and rebalancing shard distribution after resharding events.
On the exam, questions about the relationship between Kinesis consumer count and shard count appear frequently. For KCL-based consumers, the maximum number of workers equals the shard count. For Enhanced Fan-Out consumers, up to 5 registered consumers per shard can each independently receive 2MB/s. To increase throughput beyond the current shard count in KCL, resharding (increasing the number of shards) is needed, not adding more workers.
A development team is planning to deploy infrastructure changes using AWS CDK. Some team members believe that running the cdk synth command actually modifies AWS resources.
Which stage in the AWS CDK deployment process ACTUALLY creates and modifies AWS resources?
Answer: C. cdk deploy
The core of this question is distinguishing at which point in the AWS CDK deployment process actual AWS resource creation and modification occur. The cdk synth command is a synthesis step that converts CDK code into a CloudFormation template without making any AWS API calls, and actual infrastructure changes happen only with the cdk deploy command. Therefore, the assumption by some team members that cdk synth modifies resources is a misunderstanding.
AWS CDK deployment consists of three stages. cdk synth converts CDK code written in Python, TypeScript, and other languages into CloudFormation JSON/YAML templates, storing results in the cdk.out directory. cdk diff is a read-only command that retrieves and displays the differences between the currently deployed stack and the new code without modifying any AWS resources. The cdk deploy stage creates or updates the CloudFormation stack, triggering actual AWS resource creation, modification, and deletion.
Exam questions frequently ask about the role of each CDK command. Memorize: synth = synthesis (code → template, no AWS changes), diff = comparison (preview changes), deploy = actual deployment (AWS resource changes). Note that cdk bootstrap is a one-time setup command that prepares initial infrastructure such as S3 buckets and IAM roles required for CDK deployments, distinct from regular resource deployment.
A development team needs to write items across multiple DynamoDB tables so that either all items are stored simultaneously or none are, with no partial writes. Additionally, even if the same request is delivered multiple times, duplicate entries must not occur.
Which DynamoDB API BEST meets these requirements?
Answer: A. TransactWriteItems
The two most critical requirements in this scenario are atomicity — all writes across multiple tables must either succeed together or fail together — and idempotency — the same request delivered multiple times must not produce duplicate entries. TransactWriteItems is the only DynamoDB API that satisfies both conditions simultaneously, guaranteeing idempotency through the ClientRequestToken parameter.
TransactWriteItems is DynamoDB's ACID transaction API. It bundles up to 25 write requests into a single atomic unit, executing a mix of Put, Update, Delete, and ConditionCheck operations across multiple tables. If any single condition fails, the entire transaction is rolled back. When a ClientRequestToken is specified, repeated calls with the same token within 10 minutes return a success response without performing any actual writes, preventing duplicate insertions in network-retry scenarios.
On the exam, BatchWriteItem and TransactWriteItems are easy to confuse. Whenever atomicity or all-or-nothing conditions appear, you MUST select TransactWriteItems. If idempotency or duplicate-prevention keywords also appear, remember ClientRequestToken. PutItem and UpdateItem handle only single items, so they are incorrect for multi-table atomic operation scenarios.
A developer wants to verify directly in a CLI environment that newly written application code can access an Amazon S3 bucket with the permissions of a specific IAM Role.
What is the MOST appropriate method to obtain temporary credentials for the IAM Role and test the permission behavior?
Answer: C. aws sts assume-role
This question tests whether you know the method to obtain temporary credentials for a specific IAM Role and test actual permission behavior in a CLI environment. The aws sts assume-role command from AWS STS (Security Token Service) precisely meets this requirement. Running the aws sts assume-role command returns temporary credentials including AccessKeyId, SecretAccessKey, and SessionToken for the specified IAM Role, which can be set as environment variables to test CLI commands with the actual role permissions.
AWS STS is a service that provides temporary, limited-privilege credentials for AWS resources. assume-role can only be executed by principals allowed in the Role's Trust Policy, and the returned temporary credentials are valid for a default of 1 hour and up to 12 hours. Setting these credentials as AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, and AWS_SESSION_TOKEN environment variables causes all subsequent CLI commands to run with that Role's permissions.
In exam questions, distinguishing STS commands by purpose is key. Use assume-role for role assumption and permission testing, get-session-token for MFA-based temporary sessions, and assume-role-with-web-identity for web identity federation. simulate-principal-policy only performs policy evaluation simulation, making it useful for predicting permissions without actual credentials, which is different from testing actual AWS resource access.
A developer needs to use a third-party library not included in the default runtime in an AWS Lambda function. The developer needs to configure the deployment package so the library can be used in the Lambda function without additional infrastructure setup.
Which method is MOST appropriate for configuring the deployment package?
Answer: A. Lambda Layer or ZIP deployment package
A developer needs to use a third-party library not in the default runtime within Lambda, without additional infrastructure. There are two methods to use external libraries in Lambda: including them directly in a ZIP deployment package, or uploading them to a Lambda Layer and attaching it to the function. Both methods can be configured using only Lambda's own capabilities, without separate server infrastructure like EC2 or ECS.
Up to 5 Lambda Layers can be attached to a function, with each Layer having a size limit of 250 MB (uncompressed). Layers are mounted in the /opt directory, with Python automatically referencing /opt/python and Node.js referencing /opt/nodejs. A ZIP deployment package bundles function code and libraries together for independent management, but if the size becomes too large, inline console editing becomes unavailable.
On the exam, when the condition 'without additional infrastructure' appears, ECS, EC2, and Elastic Beanstalk options are all immediately wrong. If multiple Lambda functions share the same library, a Layer is BEST; if it's a single function, a ZIP package is simpler.
The AWS Developer Associate (DVA-C02) exam consists of 65 questions with a 130-minute time limit.
The passing score for the DVA-C02 exam is 720 out of 1000.
The DVA-C02 sample set (20 questions with full explanations) is free. The full bank of 470+ questions is available with a CloudMasterIT subscription.
The DVA-C02 certification is valid for 3 years after passing. Recertification is required after that.