certslothcertsloth
DVA-C02/Topic 07

AWS / Associate

DynamoDB, APIs and Application Contracts

3 min read5 recall promptsReviewed 2026-10-10

Memory hook: Access patterns choose the key; tokens identify callers; conditions protect state changes.

Must remember

  • A DynamoDB partition key distributes data; a sort key organises items within a partition. Start with required queries. Query needs partition-key equality and can constrain sort keys; Scan reads across data. A filter runs after reading and does not save the capacity of those reads.
  • GSI keys can differ from the base table and support eventual reads. LSIs retain the partition key and change the sort key, are created with the table, and have different size/consistency constraints. Base-table strong reads are an explicit choice; do not assume every index supports them.
  • Conditional writes prevent invalid transitions such as selling stock below zero. Transactions coordinate supported multi-item atomic changes; optimistic locking checks a version before an update. Idempotency records need expiration and concurrency handling, not just a cached success string.
  • TTL expires eligible items asynchronously, so expired data may remain visible until deleted. Streams expose ordered changes per item for supported consumers; consumers still need failure and duplicate handling. Cache invalidation matters with DAX and application caches; an acceleration layer cannot repair a hot key design.
  • API Gateway REST and HTTP APIs differ in features, authorisers and cost. Use stages, route/method configuration, validation and throttling appropriate to the API. CORS is a browser cross-origin permission mechanism, not authentication. An API key/usage plan is not a substitute for user authorisation.
  • Cognito user pools authenticate users and issue tokens; identity pools exchange trusted identities for temporary AWS credentials. Validate issuer, audience/client, expiry and intended token type. Use JWT/IAM/Lambda authorisers according to the API and trust model.
  • Presigned S3 URLs delegate time-bounded use of the signer's permissions. Object metadata, content type and cache headers affect clients. Multipart uploads improve large transfers but abandoned parts require cleanup. Use Secrets Manager/Parameter Store for configuration according to rotation and secrecy needs.

Choose under exam pressure

Requirement Choice and reason
Update only if the record is still version 7 Conditional write with optimistic concurrency.
Read by a different lookup key A suitable GSI, accounting for eventual consistency.
Give an authenticated mobile user scoped AWS access Identity federation/identity pool with limited roles.

Traps

  • A filter expression does not turn a Scan into a cheap key lookup.
  • TTL is not a precise deletion scheduler.
  • JWT possession is insufficient if signature, issuer and audience are not validated.

Active recall

1. Why does a filter fail to reduce read capacity as expected?

The filter is applied after the items are read.

2. Can a GSI return a strongly consistent read?

No; design for its eventual-consistency behaviour.

3. Which operation prevents two concurrent buyers from both taking the final item?

An atomic conditional update or appropriate transaction.

4. Does CORS stop a non-browser client from calling an endpoint?

No. Authorisation must be enforced by the service.

5. Why might a presigned URL stop working before its nominal expiry?

Its underlying temporary credentials can expire earlier, or applicable permissions can change.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.