certslothcertsloth
← DVA-C02 overview

Developer Associate / STUDY TOOLS

DVA-C02 quick review

Reviewed 10 October 2026 · Developer Associate

Memory hook: Caller, contract, retry owner, artifact, trace.

Development 32%; security 26%; deployment 24%; troubleshooting and optimisation 18%.

Use this as a final revision pass after the chapters. Each task below maps to the published exam outline; the outline itself is not an exhaustive list of possible questions. Recheck the official guide for your booked exam version, especially beta releases.

Must remember by exam objective

1.1 — Application code and service integration

  • Use SDK temporary credentials, pagination, bounded retries with jitter and service-specific error handling. SQS queues jobs, SNS fans out and EventBridge routes events. Step Functions coordinates durable steps; idempotent consumers prevent retries from duplicating business effects. Separate configuration and reusable clients from request-specific state.

1.2 — Lambda application behaviour

  • Synchronous callers own retries; asynchronous Lambda invocation has its own event handling; event-source mappings poll queues/streams with source-specific semantics. Execution roles permit outbound calls; resource policies permit supported invokers. Reserved concurrency caps/reserves capacity; provisioned concurrency prepares environments. VPC attachment does not create internet access.

1.3 — Application data stores

  • DynamoDB Query needs partition-key equality; filters apply after reads and do not save read capacity. GSI supports alternate keys and eventual reads; LSI keeps the partition key and can support strong reads. Conditional writes/transactions protect updates. TTL is asynchronous; S3 multipart uploads need cleanup of unfinished parts.

2.1 — Authentication and authorisation

  • Use roles/federation rather than embedded keys. Cognito user pools issue user tokens; identity pools supply temporary AWS credentials. Validate JWT signature, issuer, audience, expiry and intended token type. API keys/usage plans meter usage rather than prove authorization; CORS is browser behavior, not access control.

2.2 — Encryption

  • Use TLS in transit and suitable encryption at rest. KMS key policy/grants and data-service permissions must both permit access. Envelope encryption encrypts data with a data key and protects that key separately; key rotation does not automatically rewrite existing encrypted objects.

2.3 — Secrets and sensitive configuration

  • Secrets Manager supports secret lifecycle/rotation integrations; Parameter Store supports hierarchical configuration and SecureString. Retrieve with scoped roles, cache with a refresh policy and avoid logging secrets. Environment variables are configuration, not permission to expose credentials in artifacts or logs.

3.1 — Deployable artifacts

  • Build packages/layers or compatible container images for the runtime and CPU architecture. SAM build prepares serverless artifacts; ECR digests identify image content. Keep versions/dependencies reproducible and runtime secrets external. A mutable tag is weaker deployment evidence than an immutable digest.
  • AppConfig releases configuration/feature flags independently of application binaries. Validators, gradual deployment strategies and configured alarm rollback reduce risk; configuration changes still need compatibility tests and safe defaults.

3.2 — Development-environment testing

  • Use unit tests for logic and local tools for rapid feedback, then isolated cloud integration tests for real APIs, IAM, networking and eventual consistency. Mocked success cannot validate authorization. Keep test data and environment roles separate from production.

3.3 — Automated deployment tests

  • Use lifecycle hooks, smoke tests, contract checks and alarms to validate deployments. Canary/linear rollout limits exposure; code rollback requires compatible data/configuration. Test failure paths, throttling, duplicate events and schema evolution, not only the happy path.

3.4 — CI/CD delivery

  • CodeBuild executes buildspec phases; CodePipeline coordinates existing delivery stages; CodeDeploy manages supported rollout. Lambda versions are immutable and aliases support eligible routing. Promote the tested artifact and inspect approval/evidence. CloudFormation change sets preview infrastructure change, not application correctness.

4.1 — Root-cause investigation

  • For AccessDenied identify principal, action, resource and policy/condition layers, including KMS/endpoints. For timeouts check DNS, paths and dependency health; for throttles inspect quota, concurrency and hot keys. Diagnose failed SQS batches/stream progress using event age, retries and partial batch response behavior.

4.2 — Observability instrumentation

  • Emit structured logs/correlation IDs, meaningful metrics and distributed traces. CloudWatch Logs Insights answers focused log questions; traces reveal dependency latency and retries. Native CPU metrics cannot replace application outcomes. Redact sensitive payloads and understand sampling gaps.

4.3 — Application optimisation

  • Measure percentile latency and cost per useful operation. Tune memory/CPU, safe connection reuse, batching, keys/indexes and caches according to the actual bottleneck. DAX/caching changes freshness; more retries can increase overload. Queue long-running work when the response need not block.

Choose under exam pressure

Deciding clue Recall the distinction
One failed SQS item retries successful siblings Implement supported partial batch response and correct handler behavior.
Writes must reject stale updates Conditional write/version check; transaction for supported multi-item atomicity.
Alternate DynamoDB lookup key GSI, accounting for eventual consistency.
First call slow, warm calls meet target Measure startup and evaluate supported startup/provisioning options.
Only half the expected API list returned Follow the continuation token/paginator.

Traps

  • A Lambda asynchronous DLQ is not an SQS source redrive policy.
  • A filter does not turn a DynamoDB Scan into an inexpensive Query.
  • API keys and CORS are not substitutes for authorization.
  • AI-generated code/tests still need independent review and real acceptance evidence.

Verification cues

  • Identify invocation type before selecting retry, DLQ, batch and concurrency settings.
  • Read a SAM template/buildspec, Lambda alias/version, IAM denial and representative trace without changing deployed resources.
  • Current DVA guidance lists broader unscored emerging AI topics: assisted coding/review/testing, secure model/agent integration, deployment support and troubleshooting. Amazon Q Developer assistance also appears in the development-domain skills. Protect sensitive input/logs and validate suggestions rather than trusting generated output.

Last-pass active recall

1. Does reserved concurrency remove cold starts?

No. It reserves/caps capacity; provisioned concurrency prepares eligible environments.

2. Why can a presigned URL stop working early?

Its signing credentials or authorization can expire/revoke before the requested URL lifetime.

3. Does an LSI permit a new partition key?

No. It retains the base partition key and uses another sort key.

4. What protects a purchase from duplicate retries?

A durable idempotency key and conditional state transition around the side effect.

5. Why test a real service after local tests?

Local mocks cannot prove actual IAM, network, quota and managed-service behavior.

Sources and version check

The numbered chapters provide worked distinctions and further technical sources. These are original revision notes and original recall scenarios, not real exam questions.

Every topic at a glance

Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.

01 · IAM & AWS CLI

Memory hook: Identify who is calling, how they authenticated, and which policies authorize the exact request.

Must remember

Identities and credentials

  • The root user has special account-level capabilities. Protect it with MFA, avoid routine use, and do not create root access keys. Delegate ordinary administration; use root only when the specific operation requires it.
  • An IAM user is a persistent identity. Console passwords sign in to the console; access keys sign programmatic requests. These are different credentials.
  • An IAM group collects users and grants common permissions. Groups cannot contain other groups, are not shared logins and cannot be assumed like roles.
  • A role is an assumable identity issuing temporary credentials through AWS STS. Those credentials include an access key ID, secret key and session token, and expire.
  • Prefer federation/IAM Identity Center for workforce access and roles for applications. External SAML/OIDC identities can federate to appropriate AWS access; do not create a permanent IAM user for every workload.
  • A role's trust policy controls who can assume it; its permission policies control what the assumed identity can do. Cross-account role access needs appropriate caller authorization and target trust.
  • For EC2, an instance profile exposes the role to the instance. Lambda and other services use their own service-role arrangements; a role is not always an instance profile.

Read and evaluate a policy

  • A JSON policy contains Version and Statement; statements use Effect, Action, Resource and optional Condition. Resource policies also identify Principal. Sid is an optional statement label.
  • Version selects the policy language, not when the policy was last edited. Action identifies API capabilities; Resource identifies the affected ARN or wildcard where the action requires one.
  • Requests are implicitly denied without an applicable authorization. Explicit deny overrides allow. Conditions such as requiring secure transport determine whether a statement matches.
  • Identity policies and resource policies can participate together. Permissions boundaries, session policies and organization policies can restrict effective permissions; they do not make an otherwise unauthorized request universally allowed.
  • See advanced IAM for principal/session, boundary, SCP and cross-account nuances; “all Allows add together” is unsafe.

Authentication hygiene and evidence

  • MFA adds an authentication factor; it grants no permissions. A password policy controls IAM-user password requirements, not API key safety or federated identity-provider settings.
  • Prefer short-lived credentials and least privilege. Never embed permanent keys in source code, AMIs, user data or Terraform variables.
  • AWS CLI profiles select configuration and credentials. Environment variables or cached sessions can affect the actual caller; always distinguish intended profile from effective identity.
  • CloudShell runs a managed shell using the signed-in console identity. It is not automatically an administrator and does not bypass IAM.
  • Credential report: IAM-user credential status, password/key age and MFA information across the account.
  • Access Advisor: historical service access that helps identify overbroad permissions. Access Analyzer has different policy/resource-access analysis capabilities. History alone cannot prove a permission will never be needed.

Choose under exam pressure

Requirement or clue Decision and reason
EC2 application must read one S3 prefix Scoped instance role; no embedded keys
Employees need central multi-account login Federation/Identity Center with temporary access
Team of IAM users needs the same permissions IAM group with shared policies
Audit old or unused user credentials Credential report
Reduce unused service permissions Access Advisor plus workload requirements
Another account needs temporary access Trusted role with appropriate permissions
HTTPS required despite an identity Allow Matching explicit Deny blocks insecure requests

Traps

  • Authentication is not authorization. A valid login or API signature does not prove a requested action is allowed.
  • A policy grants nothing merely by existing. The identity attachment or resource relationship must make it applicable.
  • Display redaction is not secret protection. Local state and configuration can retain credential material even when the UI masks it.

Practise this topic

02 · Serverless services

Memory hook: Separate execution limits, data access patterns, API authorization and workflow state instead of treating serverless as unlimited capacity.

Must remember

Lambda execution, scaling and network access

  • Lambda runs event-driven functions without provisioning ordinary application servers. Handlers should tolerate retries and avoid depending on one execution environment's local state.
  • Concurrency is simultaneous execution, roughly arrival rate multiplied by execution duration. Faster functions can reduce concurrent capacity needed, but downstream services may remain the bottleneck.
  • Reserved concurrency reserves capacity and caps that function; it does not pre-initialize environments. Provisioned concurrency keeps initialized environments ready and can incur idle cost. Account quotas, function scaling behavior and throttling still apply.
  • The standard Lambda functions used in this pack have a 15-minute maximum invocation timeout. Current specialized execution modes have separate limits; do not turn that rule into a claim about every new Lambda feature. Memory also influences available CPU. Current Lambda quotas
  • SnapStart restores eligible published functions from initialized snapshots. Check runtime/feature support and handle values that must remain unique or connections that can become stale after initialization.
  • VPC attachment reaches private resources such as a private relational database. It does not give the function a public IP; a public subnet alone does not provide internet egress. Use appropriate NAT/routes or supported endpoints.
  • Supported RDS/Aurora-to-Lambda integrations let database-side activity invoke a function with suitable engine, IAM and network configuration. That is different from Lambda opening a database connection.
  • CloudFront Functions suits lightweight viewer logic; Lambda@Edge supports richer viewer/origin processing but introduces replicated-resource restrictions and slower cleanup. See global delivery.

DynamoDB access patterns, capacity and consistency

  • A table has a partition key, or a composite partition key plus sort key. The partition key distributes data; the sort key orders related items within that partition-key value.
  • Query uses a key condition to select a partition and optional sort-key range. Scan reads across the table/index. A filter is applied after reading; it does not transform an expensive scan into an efficient key lookup.
  • On-demand suits variable demand without choosing provisioned throughput. Provisioned uses read/write capacity with optional auto scaling; predictable utilization can favor explicit sizing. Item size, read consistency and transactional operations affect capacity use.
  • Capacity arithmetic: one RCU supports one strong read per second, or two eventual reads, for items up to 4 KB. One WCU supports one write per second for items up to 1 KB. Round larger items up to capacity-unit boundaries; transactions require additional capacity. Provisioned capacity
  • LSI: same partition key, different sort key; define it with the table, share table capacity, and choose eventual or strong reads.
  • GSI: a different access path using potentially different partition/sort keys; it can be added later and scales separately. GSI reads are eventually consistent, not strongly consistent. Index comparison
  • Tables and LSIs support strong reads when requested. Strong reads cost more than equivalent eventual reads; neither means every future request is protected from subsequent writes.
  • Global tables replicate across Regions. Multi-Region eventual consistency and multi-Region strong consistency are different modes with different support and tradeoffs; do not memorize “all global tables are eventually consistent.” Read consistency
  • DAX caches suitable eventually consistent DynamoDB reads. It does not remove the need for good partition keys or make a strong-read requirement a cache hit.
  • Streams captures item changes for event processing with per-item ordering; it is not permanent backup history. TTL deletes expired items asynchronously, so applications must handle records that have expired logically but remain physically present.
  • PITR and on-demand backups restore into new tables. S3 export supports analysis of point-in-time data without consuming table read capacity; S3 import creates a new table. Replication and backup protect against different failures.

API Gateway and user identity

  • REST APIs offer edge-optimized, regional and private endpoint types. HTTP APIs are a separate feature/cost choice; do not assume every REST feature exists on HTTP APIs.
  • IAM authorization uses signed AWS requests. REST APIs support Cognito user-pool authorizers; HTTP APIs have native JWT authorizers. Lambda authorizers allow custom authorization logic. REST API keys and usage plans provide client identification/metering controls, not sufficient authentication by themselves. API comparison
  • Cognito user pools provide user directories, sign-in and tokens. Identity pools exchange supported identities for temporary AWS credentials through roles, optionally including configured guest access. They solve different problems and may be combined.
  • A valid token proves an identity claim; the application still must enforce ownership of the requested record. See serverless application design.

Workflow orchestration and reusable applications

  • Step Functions models tasks, choices, parallelism, waits, retries and catches. Prefer it to implementing a long workflow through functions that poll or sleep.
  • Standard supports durable, auditable workflows up to one year and bills state transitions. Its exactly-once workflow model does not make every external side effect immune to explicitly configured retries.
  • Express supports short, high-volume workflows up to five minutes and bills execution/duration/memory. Asynchronous Express is at-least-once; synchronous Express is at-most-once. Select a model compatible with the work's idempotency and integration needs. Workflow types
  • AWS Serverless Application Repository publishes and shares deployable serverless applications, commonly described with AWS SAM. It is a reusable application catalog, not a runtime, container registry or marketplace data feed. Review permissions and created resources before deployment. Repository purpose

Choose under exam pressure

Requirement in the question Best direction
Reserve and limit a function's concurrent work Reserved concurrency
Reduce eligible initialization latency Evaluate provisioned concurrency or SnapStart
New query needs a different partition key GSI, accepting its consistency model
Immediate consistent read of a base-table item Strong table read
React to item changes DynamoDB Streams
User sign-in tokens Cognito user pool
Temporary direct AWS access for app users Cognito identity pool
Long-running auditable coordination Standard Step Functions
Reuse a packaged serverless application Serverless Application Repository

Traps

  • On-demand capacity does not eliminate hot keys, service quotas or downstream limits.
  • TTL is not an exact scheduler; a global replica is not a historical backup.
  • An LSI cannot simply be added to an existing table; a GSI cannot provide strong reads.
  • A VPC subnet labelled “public” does not give Lambda public-address connectivity.
  • Reserving concurrency is different from paying to keep environments initialized.

Practise this topic

03 · SQS, SNS, Kinesis and Amazon MQ

Memory hook: Queue work for competing workers, fan out events to independent consumers, and retain streams when replay matters.

Must remember

SQS separates arrival rate from processing rate

  • Standard queues provide at-least-once delivery and best-effort ordering. More workers can process different messages concurrently; producer and consumer availability no longer have to match exactly.
  • Retention determines how long an unprocessed message can remain. Visibility timeout temporarily hides a received message while a worker processes it. Receiving does not delete it; delete only after successful processing.
  • Set visibility around realistic processing/retry behavior. A worker can extend visibility for long work. If it crashes or visibility expires before deletion, another attempt can occur.
  • Long polling waits for available messages, reducing empty receives and their cost. It does not extend retention or the worker's processing deadline.
  • A DLQ receives messages after the configured receive-count failure threshold. Investigate and correct the cause before redriving; a DLQ is not successful completion.
  • Queue resource policies authorize cross-service or cross-account senders, often with source ARN/account conditions. Encryption and permission to send are separate controls. Visibility behavior

FIFO ordering is scoped, and business effects still need protection

  • FIFO queues preserve order within a message group. Different groups can progress independently; one global group limits parallelism.
  • Deduplication IDs prevent duplicate sends within the five-minute deduplication interval. Content-based deduplication hashes the message body, not its attributes; repeated identical bodies need deliberate identity semantics.
  • Deduplicated enqueueing is not a transaction with a payment provider or database. A worker may commit a side effect, crash before acknowledging, then receive the message again. Use an idempotency key and atomic/conditional business-state handling.
  • Moving a message out to a DLQ can interrupt an application's intended sequence. If later messages must never overtake a failed operation, design the failure workflow accordingly. FIFO deduplication

SNS distributes copies; it does not create a worker backlog by itself

  • SNS pushes messages to subscribers. Filter policies select messages by configured attributes or payload fields; they are not authorization policies.
  • SNS plus SQS fan-out gives each subscriber its own copy, buffer, scaling and retry boundary. A single shared queue instead distributes work among competing consumers.
  • SNS FIFO topics with compatible FIFO queue subscriptions support ordered fan-out; do not assume all subscriber types preserve the same ordering guarantees.
  • S3 events can publish through SNS for independent consumers. Direct S3-to-SQS-FIFO notification is unsupported; EventBridge is a supported routing alternative. See object events. Messaging choices

Streams and broker compatibility answer different requirements

  • Kinesis Data Streams retains records so independent consumers can read and replay them. A partition key maps records to a shard; ordering is scoped to the relevant shard/key, not the entire distributed workload.
  • Provisioned mode means planning shard capacity; on-demand mode reduces that capacity-management work. Neither excuses a design that sends all traffic through one hot partition key.
  • Consumers track processing position/checkpoints. Reading a record does not delete it for other applications. Retention and consumer lag determine whether replay remains possible. Kinesis Data Streams
  • Amazon Data Firehose provides managed delivery into supported destinations, with buffering and optional transformation/format conversion. Choose it when delivery is the goal; choose a stream plus consumers when custom processing/replay is the goal. Firehose's buffering is not a general-purpose long-term replay contract. Firehose
  • Amazon MQ manages supported ActiveMQ/RabbitMQ brokers. Existing JMS/AMQP-style applications that must preserve broker semantics may fit MQ better than rewriting around SQS/SNS.
  • ASG worker scaling: approximate acceptable backlog per instance as acceptable queueing delay divided by average processing time. Scale on backlog per worker, not raw queue length alone; keep retries and downstream limits in the design.

Choose under exam pressure

Requirement in the question Best direction
Buffer bursts before independent jobs SQS
Per-order sequencing with parallel unrelated orders FIFO with a group per order/workflow
Every application must receive the event SNS fan-out with separate queues
Replay telemetry through several consumers Kinesis Data Streams
Managed streaming delivery into S3 Firehose
Preserve an existing broker protocol Amazon MQ
Scale workers while meeting queueing latency Backlog per worker

Traps

  • Visibility, retention and delay are different clocks.
  • FIFO does not make an external payment automatically exactly once.
  • A filter decides delivery selection; a resource policy decides whether delivery is authorized.
  • A partition key's ordering benefit can become a throughput bottleneck when too much work shares that key.

Practise this topic

04 · S3 Introduction

Memory hook: A key names an object, versioning preserves history, and replication places eligible copies elsewhere.

Must remember

Objects, access and current limits

  • S3 stores objects: data plus metadata identified by bucket and full key. It is not an EBS block device or NFS filesystem.
  • General-purpose buckets use flat keys; slash-separated prefixes resemble folders but also support policy/lifecycle selection.
  • Names may use the shared global namespace within a partition or current account regional namespaces. The bucket's chosen Region determines data location; global naming does not imply global replication.
  • Strong read-after-write consistency covers object writes/deletes and corresponding reads/listing. Asynchronous replication and CDN caches still have independent delay.
  • Current limits, checked 2026-10-09: AWS's upload guide states a 50 TB multipart maximum; its specification expresses the bound as 48.8 TiB. Older 5 TB course limits are outdated. A single PUT remains 5 GB.
  • Multipart supports 10,000 parts, each 5 MiB–5 GiB, except no minimum for the final part. Choose adequate part sizes; unfinished parts bill until completed/aborted. See S3 operations.

Policies and website delivery

  • IAM identity policies authorize callers; bucket policies attach rules to resources. Bucket actions need bucket ARNs; object actions need appropriate object ARNs.
  • Explicit deny wins. Block Public Access restricts public exposure but does not grant private application access.
  • Bucket owner enforced Object Ownership disables ACLs and simplifies ownership; policies handle access.
  • Static websites serve HTML/JavaScript/assets, not server-side PHP or similar code. S3 website endpoints do not directly provide HTTPS.
  • Private-origin HTTPS delivery commonly uses CloudFront with S3 REST-origin/OAC. Website endpoints are custom origins with different access behavior; see edge delivery and object security.

Versions and replication

  • Versioning preserves prior data when a key is overwritten. Version ID, object key and bucket name identify different things.
  • A normal delete usually creates a delete marker; earlier versions remain billable. Deleting a specific version permanently removes that version.
  • Suspending versioning does not erase earlier history. Manage noncurrent-version retention separately from current objects.
  • CRR copies across Regions; SRR stays in one Region. Both need versioning, rules and appropriate permissions.
  • Live replication is asynchronous and normally covers eligible writes after configuration. Existing objects need explicit backfill, such as Batch Replication.
  • Delete-marker and encrypted-object replication require suitable rule/key configuration. Never assume every deletion or protection setting propagates identically.
  • A replica is not historical backup by itself; a CDN cache is not durable regional replication.

Storage classes: access, failure boundary and cost

Requirement Class and tradeoff
Frequent access and regional resilience Standard
Unknown/changing access Intelligent-Tiering, with monitoring/tiering economics
Infrequent, immediate access Standard-IA, with retrieval/minimum charges
Re-creatable infrequent data; one AZ acceptable One Zone-IA
Archive requiring immediate access Glacier Instant Retrieval
Archive tolerating restore delay Glacier Flexible Retrieval
Long archive tolerating longer recovery Glacier Deep Archive
Low-latency object access colocated in an AZ Express One Zone, using directory buckets
  • Durability means avoiding data loss; availability means successful access now. A durability figure is not an uptime percentage.
  • One Zone classes accept a different failure boundary from regional classes. Avoid storing the only irreplaceable copy there when AZ-loss survival is required.
  • Intelligent-Tiering adapts eligible access tiers; optional archive tiers change retrieval behavior. It is not guaranteed cheaper for every object.
  • Retrieval, requests, minimum duration/size and transfer charges can outweigh lower storage rates. Short-lived tiny objects are poor archival candidates.
  • Directory buckets/Express One Zone have different feature support from general-purpose buckets; do not assume identical versioning or replication behavior.

Choose under exam pressure

Requirement Decision and reason
Recover overwritten data Versioning with suitable retention
Durable copy of new writes in another Region CRR with permissions/monitoring
Replicate older objects too Explicit backfill
Private static content globally over HTTPS CloudFront and private S3 REST origin
Only copy must survive AZ loss Suitable regional storage
Archived objects need immediate reads Glacier Instant Retrieval

Traps

  • Invisible is not deleted. Versions, markers and multipart parts have independent retention.
  • Strong consistency does not control caches or replication.
  • Storage price is not total workload price. Access and retention charges can reverse apparent savings.

Practise this topic

05 · Security & Encryption

Memory hook: Protect the connection, the stored data, the permission to use it and the evidence of misuse separately.

Must remember

Encryption and key control

  • TLS protects transit; encryption at rest protects stored data. Neither prevents an already-authorized compromised application from reading plaintext. Authentication, authorization, secret handling and monitoring remain necessary.
  • KMS: AWS-owned keys are managed within services; AWS-managed keys are visible in your account but have service-controlled administration; customer-managed keys provide your own policy/lifecycle control. Symmetric encryption, asymmetric operations and HMAC keys solve different cryptographic tasks.
  • A KMS key policy is central to authorization. IAM permissions alone are not a universal substitute for a suitable key policy. Supported rotation keeps older material available for decrypting existing ciphertext; rotating a key does not automatically re-encrypt every stored object.
  • Multi-Region KMS keys share related key material, enabling supported regional cryptographic use, but policies, grants, aliases and lifecycle remain regional decisions. Creating a replica does not copy every administrative setting or automatically replicate application data.
  • Encrypted snapshot/AMI sharing needs resource permissions and appropriate customer-key access for the recipient. S3 replication of SSE-KMS objects needs explicit replication configuration, source decryption and destination encryption permissions with the correct destination key. A generic S3 copy policy is insufficient.
  • CloudHSM provides dedicated hardware security modules and more direct cryptographic control, with greater administration/capacity responsibility. Choose it for a requirement that specifically needs that control or interface; ordinary managed encryption requirements often fit KMS better.

Configuration, secrets and certificates

  • Parameter Store provides hierarchical configuration, Standard/Advanced tiers and KMS-backed SecureString. Secrets Manager supplies secret versions, supported rotation workflows and optional regional replication. Rotation requires the relevant integration and permissions; merely storing a secret does not rotate a database password.
  • Applications should retrieve secrets using a role, with caching and refresh behavior appropriate to rotation. Terraform's sensitive flag controls some display behavior; it does not encrypt local state or prevent an authorized reader from recovering supplied values.
  • ACM manages certificates. An ALB uses a certificate in its Region; CloudFront's ACM certificate must be in us-east-1. Validate domain ownership and consider the whole client-to-edge-to-origin TLS path rather than securing only one connection.
  • AWS Private CA is an adjacent distinction: it issues certificates for a private trust hierarchy, such as internal services. Private certificates are not automatically trusted by public browsers, and a private CA introduces charges. It is not separately named in the current in-scope list, unlike ACM.

Filtering, detection and investigation

  • WAF filters supported HTTP requests with web ACLs, IP sets and rules, including rate-based rules. Shield Standard supplies baseline DDoS protection; Shield Advanced adds paid capabilities. Firewall Manager centrally manages supported security policies across an organization. None replaces least privilege or secure application logic.
  • DDoS resilience combines edge absorption, caching, rate controls, suitable scaling and protected origins. Keep expensive origin work from being the first line of defense. Network Firewall handles network inspection; WAF targets supported web request paths.
  • GuardDuty detects suspicious activity. Inspector finds vulnerabilities in supported workloads. Macie discovers sensitive data in S3. Select based on the finding needed, not the generic word “security.”
  • Security Hub, including its security-posture capabilities, consolidates findings and evaluates supported security controls. Detective helps investigate relationships and activity surrounding suspicious behavior. Aggregating a finding, investigating it and automatically remediating it are different steps.
  • Artifact provides AWS compliance reports and agreements. It does not certify your application's configuration. Audit Manager can collect and organize evidence for assessments; it is useful adjacent context rather than an explicitly named service in the current list, and it does not replace the auditor's judgment.
  • Modern Inspector remains relevant; Inspector Classic is retired. Consult service status for generation-specific dates. Never infer that a current service is unavailable solely because an older namesake ended support.

Operational boundaries

  • Shared responsibility changes with the service: AWS operates underlying infrastructure, while you still control data classification, identities and workload configuration. Managing EC2 also includes guest-OS responsibilities that a fully managed service takes off your hands.
  • Choose retention deliberately. Customer-key deletion has a waiting period; secret recovery settings and replicas affect deletion; immutable compliance retention can intentionally prevent removal. Such retention is valuable when required by a real workload and incompatible with this disposable lab's default.

Choose under exam pressure

Clue in the requirement Choose or investigate
Managed encryption with controlled key permissions Customer-managed KMS key and appropriate policies
Dedicated HSM control or required cryptographic integration CloudHSM
Automatically rotate supported database credentials Secrets Manager with configured rotation
Sensitive information found in S3 objects Macie
Vulnerable supported packages or images Modern Inspector
Suspicious account/workload activity GuardDuty
Consolidated findings and posture checks Security Hub
Investigate connected security events and entities Detective
Obtain AWS's compliance documentation Artifact
Block abusive HTTP requests at CloudFront WAF rules/IP sets/rate controls

Traps

  • Encryption is not authorization, and a resource share without key access can remain unusable.
  • A managed certificate is not a domain registration; a private CA certificate is not automatically public trust.
  • A detection service is not automatically a remediation engine. Enabling broad scans or organization controls can change account behavior and spending.

Practise this topic

06 · Lambda Runtime, Events and SDK Behaviour

Memory hook: Find who invokes the function before deciding who owns retries.

Must remember

  • Synchronous invokers receive a result/error and own their retry policy. Asynchronous Lambda invocation queues an event and has configurable retry/age handling and destinations. Event-source mappings poll sources such as SQS and streams; failure handling depends on the source. Never apply one retry rule to every invocation type.
  • SQS messages remain hidden for the visibility timeout while processing. Set an adequate timeout for function execution and retry behaviour. A partial batch response can identify failed items so successful items need not be retried; the handler must implement the required response correctly. Poison messages need a bounded retry and DLQ strategy.
  • Stream ordering follows shard/partition semantics. A failed batch can stall progress; investigate record age and use supported partial-batch, batch-bisection or discard settings deliberately. Consumers must tolerate duplicate processing and checkpoints/replays.
  • Make handlers idempotent using a durable request key and conditional state transition. Reusing an execution environment permits connection reuse and cached static data, but request-specific identity or mutable state must not leak between invocations.
  • Reserved concurrency caps/reserves function concurrency within account constraints. Provisioned concurrency keeps execution environments prepared for eligible versions/aliases. Memory allocation affects CPU availability; measure duration and total cost, not just configured MB.
  • An execution role permits outbound AWS calls. Resource-based permissions authorise supported invokers. A VPC attachment provides network access, not internet access by itself: check routes, endpoints, DNS and security groups. Use an RDS Proxy when connection behaviour justifies it, rather than opening unbounded connections.
  • SDK credential chains should obtain temporary role credentials. Handle pagination, service throttling and transient errors with bounded exponential backoff and jitter. Distinguish retriable failures from invalid requests and access denial. Reuse clients where safe; never log secrets or complete sensitive payloads.

Choose under exam pressure

Requirement Choice and reason
One failed SQS item reprocesses successful siblings Implement supported partial batch failure reporting.
Warm latency is fine but cold starts breach the objective Measure and evaluate provisioned concurrency or supported startup optimisations.
A successful API returns only part of a list Follow pagination tokens.

Traps

  • A Lambda DLQ for asynchronous invocation is not the same as the source queue's redrive policy.
  • A function in a public subnet does not automatically receive public internet access.
  • Retries without idempotency can duplicate external actions.

Practise this topic

07 · DynamoDB, APIs and Application Contracts

Memory hook: Access patterns choose the key; tokens identify callers; conditions protect state changes.

Must remember

  • A DynamoDB partition key distributes data; a sort key organises items within a partition. Start with required queries. Query needs partition-key equality and can constrain sort keys; Scan reads across data. A filter runs after reading and does not save the capacity of those reads.
  • GSI keys can differ from the base table and support eventual reads. LSIs retain the partition key and change the sort key, are created with the table, and have different size/consistency constraints. Base-table strong reads are an explicit choice; do not assume every index supports them.
  • Conditional writes prevent invalid transitions such as selling stock below zero. Transactions coordinate supported multi-item atomic changes; optimistic locking checks a version before an update. Idempotency records need expiration and concurrency handling, not just a cached success string.
  • TTL expires eligible items asynchronously, so expired data may remain visible until deleted. Streams expose ordered changes per item for supported consumers; consumers still need failure and duplicate handling. Cache invalidation matters with DAX and application caches; an acceleration layer cannot repair a hot key design.
  • API Gateway REST and HTTP APIs differ in features, authorisers and cost. Use stages, route/method configuration, validation and throttling appropriate to the API. CORS is a browser cross-origin permission mechanism, not authentication. An API key/usage plan is not a substitute for user authorisation.
  • Cognito user pools authenticate users and issue tokens; identity pools exchange trusted identities for temporary AWS credentials. Validate issuer, audience/client, expiry and intended token type. Use JWT/IAM/Lambda authorisers according to the API and trust model.
  • Presigned S3 URLs delegate time-bounded use of the signer's permissions. Object metadata, content type and cache headers affect clients. Multipart uploads improve large transfers but abandoned parts require cleanup. Use Secrets Manager/Parameter Store for configuration according to rotation and secrecy needs.

Choose under exam pressure

Requirement Choice and reason
Update only if the record is still version 7 Conditional write with optimistic concurrency.
Read by a different lookup key A suitable GSI, accounting for eventual consistency.
Give an authenticated mobile user scoped AWS access Identity federation/identity pool with limited roles.

Traps

  • A filter expression does not turn a Scan into a cheap key lookup.
  • TTL is not a precise deletion scheduler.
  • JWT possession is insufficient if signature, issuer and audience are not validated.

Practise this topic

08 · Artifacts, SAM and Continuous Delivery

Memory hook: Build once, identify the artifact, test it, then move traffic deliberately.

Must remember

  • Keep source, dependencies, build instructions and infrastructure definitions versioned. CodeBuild executes a buildspec; CodePipeline coordinates stages and artifacts; CodeDeploy manages supported deployment strategies. Store immutable, identifiable artifacts in suitable S3/ECR/package repositories.
  • A Lambda deployment package must match its runtime and CPU architecture. Layers share supported dependencies; container images use a compatible runtime interface. An image tag can move: an immutable digest identifies what was actually deployed. Never bake runtime secrets into an artifact.
  • SAM expresses serverless infrastructure using a CloudFormation transform. sam build prepares artifacts; local invocation supports development feedback but cannot reproduce every cloud permission, network or managed-service behaviour. CloudFormation change sets describe proposed changes; they do not prove application correctness.
  • Test in layers: unit tests for logic, integration tests for actual service contracts, contract/schema tests for producer/consumer compatibility and end-to-end smoke tests for useful service. Mocking a success response does not validate IAM or eventual consistency.
  • Versions publish immutable Lambda configurations/code; aliases point to versions and support eligible traffic splitting. Canary exposes a small proportion first; linear shifts traffic in increments; all-at-once moves it together. Use alarms and lifecycle validation hooks to stop/roll back unsafe releases.
  • ECS blue/green deployment uses separate task sets/traffic destinations for supported controllers. EC2 deployments need healthy spare capacity and suitable hooks. Database changes require backward-compatible sequencing because rolling code back may not reverse a destructive schema change.
  • Separate development/staging/production roles and configuration. Approvals gate risk; automated tests detect behaviour. A successful pipeline means its configured steps passed, not that every failure mode has been tested.
  • AppConfig separates configuration and feature-flag release from application binaries. Validators check proposed configuration, deployment strategies control rollout, and configured alarms support rollback. A configuration change can break the application without any code deployment, so test compatibility and choose safe defaults.
  • Current emerging-topic check (10 October 2026): the official DVA-C02 guide lists broader AI-assisted code generation/review, test generation, CI/CD assistance, troubleshooting and optimisation as possible unscored pretest topics; Amazon Q Developer assistance also appears within the published development-domain skills. Treat generated code, tests and repair suggestions as proposals requiring review and representative validation. Keep secrets and personal data out of inappropriate model inputs/logs; scope agent tools and preserve explicit deployment authority. The emerging-topic list is not an additional weighted exam domain.

Choose under exam pressure

Requirement Choice and reason
Release gradually and stop on error-rate increase Canary/linear delivery with alarms and rollback.
Verify IAM against an actual database Integration test in an isolated environment.
Ensure production runs the reviewed container Pin and record the image digest.

Traps

  • Rebuilding separately in production may produce a different artifact.
  • A change set previews infrastructure actions, not test outcomes.
  • Rollback requires a compatible data and dependency state.

Practise this topic

09 · Observability, Debugging and Optimisation

Memory hook: Trace the slow request, distinguish its dependency, then measure the fix.

Must remember

  • Emit structured logs with request/correlation IDs and meaningful severity. Metrics describe rates, durations and saturation; traces follow work across components. Use CloudWatch Logs Insights for focused queries and tracing instrumentation for dependency latency. Redact credentials and personal data.
  • Instrument useful business outcomes as well as infrastructure health. A queue backlog may reveal a consumer bottleneck while CPU is low. Record failure categories, retries and downstream latency to separate cause from symptom.
  • For AccessDenied, identify the caller, action, resource, condition context and every applicable policy layer, including KMS or endpoint policies. For timeouts, check DNS, routes, security rules, connection limits and downstream health. For throttling, inspect quotas, concurrency, partition distribution and client retry behaviour.
  • Diagnose Lambda using errors, duration, throttles, concurrency and event-source age. Diagnose DynamoDB using throttled operations, key distribution, consumed capacity and query patterns. Diagnose APIs using integration latency versus total request latency, status codes and authorised/unauthorised request behaviour.
  • Caching changes freshness and invalidation requirements. Reuse safe connections, batch eligible operations and avoid repeated full-table scans. Queue long-running work when an interactive response need not wait. Tune memory or capacity using representative load tests and percentile latency.
  • A trace sample is not every request; missing instrumentation is not proof that a dependency was never called. Debug with a hypothesis, a narrow observation and a measurable acceptance condition. Preserve a rollback path and compare cost per successful operation after the change.

Choose under exam pressure

Requirement Choice and reason
Find which dependency consumed most request time Distributed trace with instrumented spans.
Find repeated errors for one correlation ID Structured logs and a scoped query.
Traffic spike creates retries and more throttling Bound retries with jitter and address the actual capacity/access-pattern limit.

Traps

  • Average latency can hide a bad tail.
  • Increasing timeout can conceal a failed dependency without fixing it.
  • Logging an access token creates a credential exposure.

Practise this topic

Search across every published topic.