Skip to content
BytePatterns

DVA-C02 · Domain 1: Development with AWS Services · 32% of the exam

Task 1.1: Develop code for applications hosted on AWS

Writing the application itself: event-driven, fan-out and orchestrated designs, synchronous versus asynchronous calls, APIs in API Gateway with validation and transformations, messaging and streaming from code, SDK calls with retries and backoff, EventBridge rules, unit tests with AWS SAM, and Amazon Q Developer as a coding aid.

Study it

  • Patterns in code: event-driven, choreography, orchestration and fan-out

    Partly covered by: Message Queues, SQS vs SNS vs EventBridge

  • Synchronous and asynchronous calls, stateless services and loose coupling

    Partly covered by: Message Queues, Vertical vs Horizontal Scaling

  • APIs with API Gateway: REST and HTTP APIs, validation, mapping templates and status codes

    Partly covered by: Designing a REST API

  • Messaging and events from code: SQS, SNS and EventBridge

    Partly covered by: SQS vs SNS vs EventBridge

  • Calling AWS from code: SDK clients, pagination, retries with backoff and idempotency

    Lesson coming

  • Resilient third-party integrations: timeouts, retries, circuit breakers

    Lesson coming

  • Streaming data: Kinesis Data Streams and DynamoDB Streams

    Lesson coming

  • Unit tests with AWS SAM and coding help from Amazon Q Developer

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A worker on Amazon EC2 calls ReceiveMessage on an Amazon SQS standard queue in a tight loop. Most responses are empty, some are empty even though messages are waiting, and the SQS request bill keeps growing. The developer wants fewer empty and false empty responses without delaying messages that are already in the queue. What should the developer do?

  1. AIncrease the queue's visibility timeout to 10 minutes
  2. BSet WaitTimeSeconds on each ReceiveMessage call to a value up to 20 seconds
  3. CMake the queue a delay queue that holds each new message for 20 seconds
  4. DKeep short polling but call ReceiveMessage from more worker threads at once
Show the answer and why
  • AIncrease the queue's visibility timeout to 10 minutes

    Incorrect

    The visibility timeout only controls how long a received message stays hidden from other consumers. It does not change how ReceiveMessage looks for messages.

  • BSet WaitTimeSeconds on each ReceiveMessage call to a value up to 20 seconds

    Correct

    A wait time above 0 turns on long polling: SQS queries all servers and answers as soon as a message is available, which cuts empty and false empty responses. The maximum wait is 20 seconds.

  • CMake the queue a delay queue that holds each new message for 20 seconds

    Incorrect

    A delay queue keeps new messages invisible for the delay period, so it delays delivery instead of reducing empty responses.

  • DKeep short polling but call ReceiveMessage from more worker threads at once

    Incorrect

    Short polling samples only a subset of servers and returns at once, even when nothing is found. More callers make more requests, not fewer empty ones.

Long polling (WaitTimeSeconds or the queue's ReceiveMessageWaitTimeSeconds above 0) is the fix for empty responses and request cost.

Question 2 · choose 1

A nightly job calls the Amazon S3 ListObjectsV2 API through an AWS SDK to process every object under the prefix invoices/. The prefix holds about 4,500 objects, but each run processes exactly 1,000 of them. The call returns no error. What should the developer change in the code?

  1. ASet MaxKeys to 5000 so that one response contains every key
  2. BAdd a Delimiter of / so that the keys come back grouped in one response
  3. CGrant the s3:ListBucket action to the job's IAM role
  4. DLoop while IsTruncated is true, passing NextContinuationToken each time
Show the answer and why
  • ASet MaxKeys to 5000 so that one response contains every key

    Incorrect

    ListObjectsV2 returns up to 1,000 keys per request, and a response never contains more than that, whatever MaxKeys asks for.

  • BAdd a Delimiter of / so that the keys come back grouped in one response

    Incorrect

    A delimiter rolls keys up into common prefixes. Each response is still limited to 1,000 entries, so the remaining keys are still missing.

  • CGrant the s3:ListBucket action to the job's IAM role

    Incorrect

    The job already lists 1,000 keys, so it has the s3:ListBucket permission the call needs. A missing permission causes an error, not a short list.

  • DLoop while IsTruncated is true, passing NextContinuationToken each time

    Correct

    When a listing is truncated, S3 returns NextContinuationToken, and the next request continues from it. SDK paginators run this loop for you.

List APIs are paginated. Read IsTruncated and follow the continuation token (or use the SDK's paginator) until the listing is complete.

Question 3 · choose 1

A REST API in Amazon API Gateway sends POST /orders to an AWS Lambda function. Many requests arrive without the required storeId query string parameter or with a JSON body that lacks required fields. Each of them still invokes the function, which then returns an error. The developer wants API Gateway to reject these requests with a 400 response before the function is invoked, without writing new code. What should the developer configure?

  1. AA request validator that requires storeId and checks the body against a model
  2. BA Lambda authorizer on the POST method that inspects the query string and the body
  3. CA usage plan with a required API key and a per-client quota on the method
  4. DA mapping template in the integration request that drops invalid fields
Show the answer and why
  • AA request validator that requires storeId and checks the body against a model

    Correct

    Basic request validation checks that required parameters are present and that the body matches the method's model schema. A failed check returns 400 without calling the backend.

  • BA Lambda authorizer on the POST method that inspects the query string and the body

    Incorrect

    A Lambda authorizer decides whether the caller may access the method and returns an IAM policy. It is code you write, and it is meant for access control, not payload validation.

  • CA usage plan with a required API key and a per-client quota on the method

    Incorrect

    Usage plans and API keys identify clients and throttle them. They do not check the parameters or body of a request.

  • DA mapping template in the integration request that drops invalid fields

    Incorrect

    A mapping template transforms the payload sent to the integration. It does not reject the request, so the function is still invoked.

Validation of required parameters and JSON schema models is built into REST APIs; it keeps bad requests away from the backend.

Question 4 · choose 1

A legacy HTTP backend returns order data as XML. A new mobile client needs the same data as JSON with different field names, and the backend team cannot change the service. The developer wants Amazon API Gateway, not new backend code, to reshape the response body. Which approach meets this requirement?

  1. AAn HTTP API route with parameter mapping that rewrites the response body
  2. BA REST API with an HTTP proxy integration to the backend
  3. CA REST API with a non-proxy integration and a response mapping template
  4. DA REST API with a Lambda authorizer that converts the response format
Show the answer and why
  • AAn HTTP API route with parameter mapping that rewrites the response body

    Incorrect

    HTTP API parameter mapping changes headers, query strings, the path and the status code. HTTP APIs do not support request or response body transformation.

  • BA REST API with an HTTP proxy integration to the backend

    Incorrect

    A proxy integration passes the backend response through. Integration response transformations need a non-proxy integration.

  • CA REST API with a non-proxy integration and a response mapping template

    Correct

    With a non-proxy integration, a REST API can transform the integration response with a mapping template before returning it, so the body can be rewritten from XML to the JSON shape the client needs.

  • DA REST API with a Lambda authorizer that converts the response format

    Incorrect

    A Lambda authorizer runs before the integration and returns an IAM policy that allows or denies the call. It never sees the backend response.

Body transformation is a REST API feature: a non-proxy integration plus mapping templates. HTTP APIs offer parameter mapping only.

Question 5 · choose 1

An order service publishes an OrderPlaced event to a custom Amazon EventBridge event bus for every order. The event's detail.total field is a number. A fraud-check workflow must start only for orders with a total above 1,000, and other orders must not reach it. Which solution needs the least custom code?

  1. AA rule whose event pattern uses numeric matching on detail.total
  2. BA rule with an input transformer that passes only detail.total to the target
  3. CA rule that matches every order, with a Lambda target that checks the total and starts the workflow
  4. DAn archive on the bus that keeps large orders, replayed to the bus every hour
Show the answer and why
  • AA rule whose event pattern uses numeric matching on detail.total

    Correct

    Event patterns support numeric comparisons such as greater than, so the rule matches only the events above the threshold and routes them to the workflow.

  • BA rule with an input transformer that passes only detail.total to the target

    Incorrect

    An input transformer changes the text sent to the target. It does not decide which events match, so every order would still start the workflow.

  • CA rule that matches every order, with a Lambda target that checks the total and starts the workflow

    Incorrect

    This works, but it adds a function to write and run for a filter that the event pattern can express by itself.

  • DAn archive on the bus that keeps large orders, replayed to the bus every hour

    Incorrect

    Archive and replay resend past events to the bus later, for recovery or testing. The replayed events still need a rule, and checks would start up to an hour late.

Filter in the event pattern: content filtering, including numeric ranges, is part of EventBridge rules.

Question 6 · choose 2

An AWS Lambda function calls a third-party shipping-rate API over HTTPS. The API sometimes returns HTTP 503 for a few seconds. At other times it stops answering, and the invocation waits until the function's 60-second timeout and fails. Which TWO changes make this integration more resilient? (Choose TWO.)

  1. ARaise the function timeout to 15 minutes so that slow calls can finish
  2. BSet a client timeout of a few seconds on the HTTP call, well below the function timeout
  3. CRetry failed calls at once, in a loop, until the API answers
  4. DRetry 503 responses a limited number of times with exponential backoff and jitter
  5. ESet the function's reserved concurrency to 1 so that only one call reaches the API at a time
Show the answer and why
  • ARaise the function timeout to 15 minutes so that slow calls can finish

    Incorrect

    A longer function timeout only lets a hung call wait longer and hold concurrency. Timeouts should be set from what the workload needs, not stretched to the maximum.

  • BSet a client timeout of a few seconds on the HTTP call, well below the function timeout

    Correct

    An explicit client timeout stops the code from waiting on a call that will not answer, so it can back off and retry, or fail fast, while the function still has time left.

  • CRetry failed calls at once, in a loop, until the API answers

    Incorrect

    Retrying without backoff, jitter or a maximum number of attempts creates a burst of traffic against a service that is already struggling.

  • DRetry 503 responses a limited number of times with exponential backoff and jitter

    Correct

    A 503 for a few seconds is a transient error. Capped retries with growing, randomized waits give the API time to recover without synchronized retry spikes.

  • ESet the function's reserved concurrency to 1 so that only one call reaches the API at a time

    Incorrect

    Reserved concurrency of 1 caps the function at one concurrent instance, so all other requests are throttled. A hung call still waits until the function times out.

Resilient clients bound every remote call with a timeout and retry only transient failures, with exponential backoff, jitter and a retry limit; a circuit breaker can add a fail-fast path for longer outages.

Question 7 · choose 1

Clients start a report through a route on an HTTP API in Amazon API Gateway. The AWS Lambda function behind the route now needs 3 to 5 minutes to build a report. Clients receive a timeout error after 30 seconds, even though the function finishes later. The team must keep the HTTP API. What should the developer do?

  1. ARaise the integration timeout of the HTTP API route to 5 minutes
  2. BRaise the Lambda function timeout to 10 minutes and redeploy it
  3. CTurn on response caching so that repeated calls return at once
  4. DReturn 202 with a job ID and build the report from an Amazon SQS queue
Show the answer and why
  • ARaise the integration timeout of the HTTP API route to 5 minutes

    Incorrect

    The maximum integration timeout for HTTP APIs is 30 seconds, and this quota cannot be increased.

  • BRaise the Lambda function timeout to 10 minutes and redeploy it

    Incorrect

    The function may already finish, but API Gateway stops waiting for the integration after 30 seconds, so clients still time out.

  • CTurn on response caching so that repeated calls return at once

    Incorrect

    HTTP APIs do not offer API caching, and a cache would not help the first request for each report anyway.

  • DReturn 202 with a job ID and build the report from an Amazon SQS queue

    Correct

    Making the work asynchronous keeps the API call short. An HTTP API can send the request straight to SQS with a first-class integration, and a consumer processes it while the client checks the job status.

When work takes longer than the API's integration timeout, accept the request, queue it, and let the client pick up the result later.

Question 8 · choose 1

A team writes Python services in Visual Studio Code. The developers want an assistant in the IDE that suggests code inline as they type, writes new code from a chat request, and scans their code for security vulnerabilities. Which AWS service provides these capabilities?

  1. AAWS CloudShell
  2. BAmazon Q Developer
  3. CAWS X-Ray
  4. DAWS Cloud Development Kit (AWS CDK)
Show the answer and why
  • AAWS CloudShell

    Incorrect

    CloudShell is a browser-based, pre-authenticated shell for running the AWS CLI and other tools. It does not suggest or review code in an IDE.

  • BAmazon Q Developer

    Correct

    Used in an IDE, Amazon Q Developer can chat about code, give inline code completions, generate new code and scan code for security vulnerabilities.

  • CAWS X-Ray

    Incorrect

    X-Ray collects data about the requests an application serves so that developers can trace and analyze them. It does not write code.

  • DAWS Cloud Development Kit (AWS CDK)

    Incorrect

    The AWS CDK is a framework for defining cloud infrastructure in code and provisioning it through CloudFormation. It does not suggest or scan code.

Amazon Q Developer is the generative AI assistant for development work in the IDE: completions, code generation, and security scanning.

Question 9 · choose 1

A browser application on https://app.example.com calls an Amazon API Gateway REST API on a different domain. The API's methods use Lambda proxy integration. The browser blocks the responses with a CORS error, even though the developer enabled CORS on the resource in the console. What should the developer do?

  1. AReturn the Access-Control-Allow-Origin and related headers from the Lambda function
  2. BAdd the browser's origin to the API's resource policy
  3. CTurn on a Lambda authorizer that allows requests from the browser
  4. DSwitch the API to an edge-optimized endpoint
Show the answer and why
  • AReturn the Access-Control-Allow-Origin and related headers from the Lambda function

    Correct

    With a proxy integration there is no integration response to add headers to, so the backend must return the CORS headers itself.

  • BAdd the browser's origin to the API's resource policy

    Incorrect

    A resource policy controls who may invoke the API; it does not add CORS headers to responses.

  • CTurn on a Lambda authorizer that allows requests from the browser

    Incorrect

    Authorizers decide access; the browser still needs CORS headers in the response.

  • DSwitch the API to an edge-optimized endpoint

    Incorrect

    The endpoint type does not change which headers the backend returns.

For Lambda or HTTP proxy integrations, CORS headers must come from the backend because API Gateway passes its response through.

Question 10 · choose 1

A team is building a new public API for a mobile app. Every route invokes an AWS Lambda function, and users are authorized with JSON web tokens from an OpenID Connect provider. The API needs no API keys, per-client throttling, request validation or AWS WAF. The team wants the lowest price. Which API Gateway option should the developer choose?

  1. AA private REST API with a resource policy
  2. BA REST API with a Lambda authorizer that validates the tokens
  3. CA WebSocket API with a route per operation
  4. DAn HTTP API with a JWT authorizer and Lambda integrations
Show the answer and why
  • AA private REST API with a resource policy

    Incorrect

    Private APIs are reachable only from VPCs, so a public mobile app could not call it.

  • BA REST API with a Lambda authorizer that validates the tokens

    Incorrect

    REST APIs offer more features at a higher price, and none of those extra features are needed here.

  • CA WebSocket API with a route per operation

    Incorrect

    WebSocket APIs are for persistent two-way connections, not ordinary request and response calls.

  • DAn HTTP API with a JWT authorizer and Lambda integrations

    Correct

    HTTP APIs have minimal features at a lower price and support JWT authorizers natively.

Choose REST APIs when you need their extra features; otherwise HTTP APIs cost less and support JWT authorization.

Question 11 · choose 1

An Amazon EventBridge rule sends order events to a partner's webhook through an API destination. The partner accepts only a small JSON body with three fields taken from the event, under different field names. The developer does not want to add a function just to reshape events. What should the developer configure?

  1. AA second event bus that receives copies of the events
  2. BAn input transformer on the rule's target
  3. CAn event pattern that matches only the three fields
  4. DAn archive with a replay to the API destination
Show the answer and why
  • AA second event bus that receives copies of the events

    Incorrect

    Another bus moves the same events; it does not change their shape.

  • BAn input transformer on the rule's target

    Correct

    An input transformer uses an input path and an input template to customize the event text before it is sent to the target.

  • CAn event pattern that matches only the three fields

    Incorrect

    Event patterns decide which events match; they do not change the event that is delivered.

  • DAn archive with a replay to the API destination

    Incorrect

    Archive and replay resend past events unchanged; they do not reshape them.

Input transformers reshape events for targets without extra code.

Question 12 · choose 1

An AWS Step Functions Standard workflow starts an Amazon ECS task on AWS Fargate to transcode a file, and the next state must run only after the task has finished. Today a Lambda function polls the task status in a loop with Wait states. How can the developer simplify the workflow?

  1. ACall ecs:runTask with the .sync pattern so the state waits for the task
  2. BUse the Request Response pattern and add a long Wait state after it
  3. CSwitch the workflow to an Express workflow
  4. DStart the task from a Lambda function invoked with the Event invocation type
Show the answer and why
  • ACall ecs:runTask with the .sync pattern so the state waits for the task

    Correct

    With the Run a Job (.sync) pattern, Step Functions calls the service and waits for the job to complete before moving on.

  • BUse the Request Response pattern and add a long Wait state after it

    Incorrect

    Request Response moves on as soon as the call returns, so a fixed wait guesses at the task's run time.

  • CSwitch the workflow to an Express workflow

    Incorrect

    The workflow type does not make the state wait for the task; Express workflows also run for at most five minutes.

  • DStart the task from a Lambda function invoked with the Event invocation type

    Incorrect

    Asynchronous invocation returns at once and does not report when the task finishes.

Optimized integrations such as ECS support .sync, which removes polling code from workflows.

Question 13 · choose 1

An Amazon SQS queue is subscribed to an Amazon SNS topic. The consumer code expects the original JSON message published to the topic, but each SQS message body arrives wrapped in a JSON document with SNS metadata. What should the developer change so that the body is the original message?

  1. ATurn on raw message delivery for the subscription
  2. BAdd a subscription filter policy for the message attributes
  3. CTurn on long polling for the queue
  4. DChange the queue to a FIFO queue
Show the answer and why
  • ATurn on raw message delivery for the subscription

    Correct

    Raw message delivery sends the message as published, without the JSON formatting that SNS otherwise adds.

  • BAdd a subscription filter policy for the message attributes

    Incorrect

    Filter policies choose which messages are delivered; they do not change the message format.

  • CTurn on long polling for the queue

    Incorrect

    Long polling affects how consumers receive messages, not their content.

  • DChange the queue to a FIFO queue

    Incorrect

    FIFO changes ordering and deduplication, not the SNS wrapper.

Raw message delivery removes the SNS envelope for SQS and HTTP/S subscribers.

Practise domain 1 →Practise all domains →