Skip to content
BytePatterns

DVA-C02 · Domain 1: Development with AWS Services · 32% of the exam

Task 1.2: Develop code for AWS Lambda

Everything a function needs to run well: memory, timeout, concurrency, environment variables, layers and extensions, event sources and triggers, destinations and dead-letter queues for failures, reaching resources inside a VPC, testing, and processing streams in near real time.

Study it

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

Amazon S3 event notifications invoke an AWS Lambda function asynchronously. For every event that Lambda stops processing, the team wants a single JSON document that holds the original event, the function's full response payload, the condition that ended processing, and how many times the function was invoked. Which configuration meets this requirement without code changes?

  1. AAn Amazon SQS standard queue as the function's dead-letter queue
  2. BRetry attempts set to 0 for asynchronous invocations
  3. CAn Amazon SQS standard queue as an on-failure destination
  4. DA maximum event age of 6 hours so that failed events stay in Lambda's queue
Show the answer and why
  • AAn Amazon SQS standard queue as the function's dead-letter queue

    Incorrect

    Lambda sends the event as-is, adding only RequestID, ErrorCode and the first 1 KB of the error message as message attributes. There is no response payload, no attempt count and no condition.

  • BRetry attempts set to 0 for asynchronous invocations

    Incorrect

    Fewer retries only make Lambda discard a failing event sooner. Nothing is kept unless a destination or dead-letter queue is configured.

  • CAn Amazon SQS standard queue as an on-failure destination

    Correct

    Lambda sends one invocation record in JSON with the request payload, the response payload, and a request context that includes the condition, such as RetriesExhausted, and approximateInvokeCount.

  • DA maximum event age of 6 hours so that failed events stay in Lambda's queue

    Incorrect

    The maximum event age limits how long an event may wait in the asynchronous queue. When an event fails all retries or exceeds that age, Lambda discards it.

Dead-letter queues and on-failure destinations both catch events that failed all attempts or expired. A dead-letter queue keeps the event plus three attributes; only a destination's invocation record adds the full response, the condition and the invoke count.

Question 2 · choose 1

An AWS Lambda function reads batches of 10 messages from an Amazon SQS standard queue and sends one email per message. When a single message fails, the function throws an exception, all 10 messages become visible again, and customers receive duplicate emails for the 9 messages that had already succeeded. The developer must stop this without lowering throughput. What should the developer do?

  1. ATurn on ReportBatchItemFailures and return the failed message IDs
  2. BIncrease the queue's visibility timeout to six times the function timeout
  3. CAdd a dead-letter queue to the source queue with a maxReceiveCount of 1
  4. DKeep the exception but let Lambda retry the whole batch with a bigger batch window
Show the answer and why
  • ATurn on ReportBatchItemFailures and return the failed message IDs

    Correct

    With a partial batch response, the function catches its errors and returns the IDs of the failed messages, and only those messages become visible again.

  • BIncrease the queue's visibility timeout to six times the function timeout

    Incorrect

    A longer visibility timeout changes when messages reappear, not which ones. After a thrown exception, the whole batch still returns.

  • CAdd a dead-letter queue to the source queue with a maxReceiveCount of 1

    Incorrect

    With maxReceiveCount set to 1, one failed receive moves a message to the dead-letter queue. The nine messages that already succeeded would land there as failures too.

  • DKeep the exception but let Lambda retry the whole batch with a bigger batch window

    Incorrect

    When the function throws an exception, Lambda treats the entire batch as failed, so successful messages are processed again whatever the batch window is.

Partial batch responses (ReportBatchItemFailures plus a batchItemFailures list) are the way to retry only the messages that failed.

Question 3 · choose 1

An AWS Lambda function must read from an Amazon RDS database in the private subnets of a VPC and must also call a payment provider's public API on the internet. After the developer connects the function to the VPC, the database queries work, but every call to the public API times out. What should the developer do?

  1. AConnect the function to the VPC's public subnets, which route to an internet gateway
  2. BConnect the function to private subnets that route internet traffic to a NAT gateway
  3. CAdd a gateway VPC endpoint for the payment provider's API
  4. DIncrease the function timeout so that the calls to the public API can finish
Show the answer and why
  • AConnect the function to the VPC's public subnets, which route to an internet gateway

    Incorrect

    Connecting a function to a public subnet does not give it internet access or a public IP address.

  • BConnect the function to private subnets that route internet traffic to a NAT gateway

    Correct

    A VPC-connected function reaches the internet from private subnets through a NAT gateway in a public subnet, while it keeps its private path to the database.

  • CAdd a gateway VPC endpoint for the payment provider's API

    Incorrect

    Gateway VPC endpoints exist only for Amazon S3 and DynamoDB. They cannot reach a third-party API on the internet.

  • DIncrease the function timeout so that the calls to the public API can finish

    Incorrect

    The calls fail because the function has no route to the internet. More time does not create a route.

Inside a VPC, a Lambda function needs private subnets plus a NAT gateway to reach the internet; public subnets alone are not enough.

Question 4 · choose 1

Twelve Python AWS Lambda functions each bundle the same internal data-access library and its dependencies in their .zip deployment packages. Every fix to the library means rebuilding and redeploying all twelve packages. The developer wants to package the library once, keep it separate from the function code, and use it from every function. What should the developer do?

  1. APublish the library to AWS CodeArtifact so that Lambda installs it when a function starts
  2. BPackage the library as a Lambda extension that each function loads
  3. CTurn on provisioned concurrency so that the library is loaded only once
  4. DPublish the library as a Lambda layer and add the layer to the twelve functions
Show the answer and why
  • APublish the library to AWS CodeArtifact so that Lambda installs it when a function starts

    Incorrect

    CodeArtifact is a package repository for package managers such as pip. Installing from it is a build step, so every deployment package would still carry its own copy of the library.

  • BPackage the library as a Lambda extension that each function loads

    Incorrect

    Extensions integrate functions with tools such as monitoring, observability, security and governance agents. They are not the way to share a code library.

  • CTurn on provisioned concurrency so that the library is loaded only once

    Incorrect

    Provisioned concurrency keeps execution environments initialized ahead of time. Each function still carries its own copy of the library.

  • DPublish the library as a Lambda layer and add the layer to the twelve functions

    Correct

    A layer is a .zip archive of shared code or dependencies. It can be added to any number of functions and updated separately from the function code.

Layers keep shared dependencies out of each deployment package, so they are built once and versioned on their own.

Question 5 · choose 1

A REST API in Amazon API Gateway invokes an AWS Lambda function synchronously. Each function instance opens one connection to a legacy database that accepts at most 50 connections. During traffic spikes the database refuses connections and the API returns errors. The developer must make sure that no more than 50 instances of the function ever run at the same time. What should the developer configure?

  1. AProvisioned concurrency of 50 on the function's alias
  2. BMaximum concurrency of 50 on the function's event source mapping
  3. CReserved concurrency of 50 on the function
  4. DA function timeout of 50 seconds so that idle connections close sooner
Show the answer and why
  • AProvisioned concurrency of 50 on the function's alias

    Incorrect

    Provisioned concurrency pre-initializes environments to cut cold starts. Beyond it, the function keeps scaling on unreserved concurrency, so it is not a cap.

  • BMaximum concurrency of 50 on the function's event source mapping

    Incorrect

    Maximum concurrency is a scaling setting of SQS event source mappings. API Gateway invokes the function directly, so there is no event source mapping to limit.

  • CReserved concurrency of 50 on the function

    Correct

    Reserved concurrency sets both the minimum and the maximum number of concurrent instances, so the function cannot scale past 50 and overwhelm the database.

  • DA function timeout of 50 seconds so that idle connections close sooner

    Incorrect

    The timeout limits how long one invocation may run. It does not limit how many invocations run at the same time.

Reserved concurrency is the per-function cap that protects a downstream resource; provisioned concurrency is about latency, not limits.

Question 6 · choose 2

An AWS Lambda function reads an Amazon Kinesis data stream through an event source mapping that uses the default settings. One malformed record makes the function throw an error, and processing of that shard has stopped while the iterator age keeps growing. The team wants the shard to move on after a few attempts and wants to keep information about the failed batches for later analysis. Which TWO changes should the developer make? (Choose TWO.)

  1. ASet MaximumRetryAttempts on the event source mapping to a small number, such as 2
  2. BAdd an Amazon SQS dead-letter queue to the function's asynchronous invocation settings
  3. CIncrease the batch size on the event source mapping to 1,000 records
  4. DIncrease the function's memory so that the malformed record is processed faster
  5. EConfigure an on-failure destination, such as an SQS queue, on the event source mapping
Show the answer and why
  • ASet MaximumRetryAttempts on the event source mapping to a small number, such as 2

    Correct

    By default, failed records are retried until they expire, which can block a shard for up to a week. A retry limit lets Lambda discard the batch and continue with the shard.

  • BAdd an Amazon SQS dead-letter queue to the function's asynchronous invocation settings

    Incorrect

    Asynchronous dead-letter queues apply to asynchronous invocations. A Kinesis event source mapping keeps failed batches through an on-failure destination on the mapping itself.

  • CIncrease the batch size on the event source mapping to 1,000 records

    Incorrect

    A larger batch still contains the malformed record, and with the default settings Lambda keeps retrying it until it expires.

  • DIncrease the function's memory so that the malformed record is processed faster

    Incorrect

    More memory adds CPU, but the record fails because of its content, so the error and the retries continue.

  • EConfigure an on-failure destination, such as an SQS queue, on the event source mapping

    Correct

    When the retries are exhausted, Lambda sends a JSON record with metadata about the failed batch to the on-failure destination for later processing.

For streams, bound the retries (MaximumRetryAttempts or MaximumRecordAgeInSeconds) and keep what was discarded with an on-failure destination on the event source mapping.

Question 7 · choose 1

A product catalog is stored in an Amazon DynamoDB table, and shoppers search it through an Amazon OpenSearch Service index. The index must reflect every insert, update and delete within seconds. The services that write to the table must not change. Which solution meets these requirements?

  1. AAn Amazon EventBridge Scheduler schedule that runs a Lambda function every hour to rebuild the index
  2. BDynamoDB Streams with a Lambda trigger that writes each change to the index
  3. CTime to Live (TTL) on the table so that changed items are copied to the index
  4. DA global secondary index that projects all attributes, used as the search source
Show the answer and why
  • AAn Amazon EventBridge Scheduler schedule that runs a Lambda function every hour to rebuild the index

    Incorrect

    A schedule runs work at set times, so changes would reach the index up to an hour late instead of within seconds.

  • BDynamoDB Streams with a Lambda trigger that writes each change to the index

    Correct

    DynamoDB Streams records every item-level modification in near real time, and a Lambda trigger can apply each stream record to the search index without touching the writers.

  • CTime to Live (TTL) on the table so that changed items are copied to the index

    Incorrect

    TTL deletes items after their expiration timestamp. It does not copy inserts or updates anywhere.

  • DA global secondary index that projects all attributes, used as the search source

    Incorrect

    A global secondary index is another DynamoDB index on the same data. It does not send changes to OpenSearch Service.

Change data capture with DynamoDB Streams and a Lambda trigger keeps a derived store such as a search index in step with the table.

Question 8 · choose 1

An AWS Lambda function's prod alias points to published version 7. A developer changes the function's memory setting in the console and saves, but production invocations through the prod alias still run with the old memory. What explains this, and what should the developer do?

  1. AThe change needs a few hours to propagate to the alias, so wait for it
  2. BAliases cache settings, so delete and recreate the prod alias
  3. CThe change went to $LATEST; publish a new version and point prod to it
  4. DMemory can only be changed through AWS CloudFormation, so redeploy the stack
Show the answer and why
  • AThe change needs a few hours to propagate to the alias, so wait for it

    Incorrect

    There is no such delay; the alias points to a published version whose settings do not change.

  • BAliases cache settings, so delete and recreate the prod alias

    Incorrect

    Recreating the alias still points it at version 7, whose memory setting is unchanged.

  • CThe change went to $LATEST; publish a new version and point prod to it

    Correct

    A published version's code and most settings, including memory, are immutable, so changes made to $LATEST need a new version.

  • DMemory can only be changed through AWS CloudFormation, so redeploy the stack

    Incorrect

    Memory can be changed in the console, CLI or API; the issue is which version was changed.

Edits go to $LATEST; published versions are immutable, so release changes by publishing a version and moving the alias.

Question 9 · choose 1

An AWS Lambda function deployed as a .zip file archive already uses five layers. A developer tries to add a sixth layer with a small shared library and the update fails. The function and its layers together are well under the unzipped size quota. What should the developer do?

  1. AAttach the sixth layer to an alias of the function instead
  2. BUpload the sixth layer through Amazon S3 so that it is not counted toward the limit
  3. CPublish the sixth layer in another account and reference it there
  4. DCombine the new library with one of the existing layers into one layer
Show the answer and why
  • AAttach the sixth layer to an alias of the function instead

    Incorrect

    Layers are part of the function's configuration, not of an alias, and the same per-function limit applies.

  • BUpload the sixth layer through Amazon S3 so that it is not counted toward the limit

    Incorrect

    Uploading through S3 helps with large archives; every attached layer still counts toward the limit.

  • CPublish the sixth layer in another account and reference it there

    Incorrect

    Layers from other accounts count toward the same per-function limit.

  • DCombine the new library with one of the existing layers into one layer

    Correct

    A function can have up to five layers, so merging content into an existing layer keeps the count within the limit.

A function can use at most five layers, within a 250 MB unzipped total for the function and its layers.

Question 10 · choose 1

One AWS Lambda function consumes two Amazon SQS queues: an orders queue that needs fast processing and a bulk-reports queue that sometimes receives millions of messages at once. During bulk floods, the reports queue uses so much concurrency that orders wait. The developer wants to cap the reports queue at 20 concurrent invocations without capping the orders queue. What should the developer configure?

  1. AReserved concurrency of 20 on the function
  2. BA smaller batch size on the reports queue's event source mapping
  3. CMaximum concurrency of 20 on the reports queue's event source mapping
  4. DA longer visibility timeout on the reports queue so messages wait longer
Show the answer and why
  • AReserved concurrency of 20 on the function

    Incorrect

    Reserved concurrency caps the whole function, so the orders queue would also be limited to 20.

  • BA smaller batch size on the reports queue's event source mapping

    Incorrect

    Smaller batches mean more invocations for the same messages, which uses more concurrency, not less.

  • CMaximum concurrency of 20 on the reports queue's event source mapping

    Correct

    Maximum concurrency limits how many concurrent instances one SQS event source can invoke, set per event source mapping.

  • DA longer visibility timeout on the reports queue so messages wait longer

    Incorrect

    Visibility timeout controls when unprocessed messages reappear; it does not limit concurrent invocations.

Use per-event-source maximum concurrency to keep one queue from taking all of a function's concurrency.

Question 11 · choose 1

A team learns that the managed runtime used by several of its AWS Lambda functions is scheduled for deprecation. The functions work today, and the team wants to keep receiving security patches and to avoid being blocked from updating the functions later. What should the developer do?

  1. ANothing; deprecated runtimes keep receiving patches as long as they are invoked
  2. BMove to a supported runtime after testing, using versions and aliases
  3. CKeep deploying to the old runtime after updates are blocked by using the API
  4. DCopy the functions into a new account where the runtime is still allowed
Show the answer and why
  • ANothing; deprecated runtimes keep receiving patches as long as they are invoked

    Incorrect

    After deprecation, AWS may no longer apply security patches or updates to the runtime.

  • BMove to a supported runtime after testing, using versions and aliases

    Correct

    AWS recommends migrating to a supported runtime, testing first and using versions and aliases for safe deployment with rollback.

  • CKeep deploying to the old runtime after updates are blocked by using the API

    Incorrect

    Once function updates are blocked, the deprecated runtime cannot be chosen again, whatever tool is used.

  • DCopy the functions into a new account where the runtime is still allowed

    Incorrect

    Runtime deprecation is not tied to one account, so moving the functions does not avoid it.

Plan runtime upgrades before deprecation dates, and release them safely with versions and aliases.

Question 12 · choose 1

At initialization, a Node.js AWS Lambda function written as an ES module starts a call that reads a value from Parameter Store, but it does not wait for the call to finish. On some first invocations the value is undefined and requests fail. What should the developer change?

  1. ARaise the function's memory so that initialization runs faster
  2. BMove the call into a setTimeout callback with a short delay
  3. CUse top-level await so that the call completes during initialization
  4. DSwitch the handler to a callback-style handler that calls back at the end
Show the answer and why
  • ARaise the function's memory so that initialization runs faster

    Incorrect

    Faster initialization does not guarantee that an unawaited call has finished before the handler runs.

  • BMove the call into a setTimeout callback with a short delay

    Incorrect

    A timer guesses at timing; the value can still be missing when the handler runs.

  • CUse top-level await so that the call completes during initialization

    Correct

    With ES modules, top-level await completes asynchronous tasks during initialization, so the value is ready before the first invocation.

  • DSwitch the handler to a callback-style handler that calls back at the end

    Incorrect

    AWS recommends async/await over callbacks, and the style of the handler does not finish the initialization call.

Asynchronous work started at init must be awaited, or it may run during the first invocation instead.

Practise domain 1 →Practise all domains →