Skip to content
BytePatterns

DVA-C02 · Domain 3: Deployment · 24% of the exam

Task 3.1: Prepare application artifacts to be deployed to AWS

Getting a build ready to ship: dependencies, layers and container images, the directory layout each service expects, repositories and artifact stores, memory and CPU settings, and per-environment configuration with AWS AppConfig and Parameter Store.

Study it

  • Packaging: .zip archives, layers and container images

    Partly covered by: Images, Layers & Multi-Stage Builds

  • Configuration per environment: AWS AppConfig, Parameter Store and environment variables

    Partly covered by: ConfigMaps, Secrets & Env

  • Repositories and artifact stores: Git, CodeArtifact and Amazon ECR

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A Python AWS Lambda function needs machine learning libraries that take about 1.2 GB once unpacked. Deploying it as a .zip archive fails because of the package size. The team wants to keep running the code on Lambda. How should the developer package the function?

  1. AAs a container image in Amazon ECR, built from an AWS base image for Lambda
  2. BAs a smaller .zip with the libraries split across five Lambda layers
  3. CAs the same .zip archive, uploaded through Amazon S3 instead of directly
  4. DAs the same .zip archive, with the function's memory raised to 10,240 MB
Show the answer and why
  • AAs a container image in Amazon ECR, built from an AWS base image for Lambda

    Correct

    A container image can be up to 10 GB uncompressed, including all of its layers, which fits the libraries.

  • BAs a smaller .zip with the libraries split across five Lambda layers

    Incorrect

    The 250 MB unzipped limit covers the deployment package together with its layers, so splitting the libraries into layers does not help.

  • CAs the same .zip archive, uploaded through Amazon S3 instead of directly

    Incorrect

    Uploading through S3 avoids the 50 MB limit for direct uploads, but the 250 MB limit on the unzipped contents still applies.

  • DAs the same .zip archive, with the function's memory raised to 10,240 MB

    Incorrect

    Memory sets the function's runtime memory and CPU. It does not change the size limits of the deployment package.

.zip packages, layers included, are limited to 250 MB unzipped; container images allow up to 10 GB.

Question 2 · choose 1

A new checkout feature is already deployed to an Amazon ECS service but is turned off. The team wants to turn it on without redeploying the service, check that the configuration is valid JSON before it goes out, expose it to callers gradually over 30 minutes, and roll back automatically if a CloudWatch alarm fires. Which approach meets these requirements?

  1. AA Parameter Store parameter that the service reads on every request
  2. BAn AWS AppConfig feature flag with a validator, a linear strategy and an alarm
  3. CA Secrets Manager secret that holds the flag, rotated every 30 minutes
  4. DA JSON file in a versioned S3 bucket, restored to an older version on problems
Show the answer and why
  • AA Parameter Store parameter that the service reads on every request

    Incorrect

    A parameter update takes effect on the next read, with no validation, gradual rollout or automatic revert.

  • BAn AWS AppConfig feature flag with a validator, a linear strategy and an alarm

    Correct

    AppConfig validates configuration before deployment, rolls it out gradually with a deployment strategy, and rolls back automatically when a monitored CloudWatch alarm goes into alarm.

  • CA Secrets Manager secret that holds the flag, rotated every 30 minutes

    Incorrect

    Secrets Manager rotation updates credentials on a schedule. It does not validate configuration or expose a change gradually.

  • DA JSON file in a versioned S3 bucket, restored to an older version on problems

    Incorrect

    Versioning lets someone restore an earlier version, but validation, gradual exposure and alarm-driven rollback would all be custom work.

Feature flags with validators, deployment strategies and alarm-based rollback are what AWS AppConfig adds on top of plain configuration storage.

Question 3 · choose 1

A team publishes private npm packages and also depends on public packages from npmjs.com. Builds in AWS CodeBuild must install both kinds from a single registry endpoint, and the public packages they use should be fetched once and then kept in AWS so that later builds do not depend on npmjs.com. What should the developer set up?

  1. AAn Amazon ECR pull through cache rule that syncs npmjs.com
  2. BA Lambda layer that holds the npm packages, attached to the build project
  3. CA CodeArtifact repository whose upstream has an external connection to npmjs.com
  4. DA CodeArtifact repository without an external connection, filled by hand with public packages
Show the answer and why
  • AAn Amazon ECR pull through cache rule that syncs npmjs.com

    Incorrect

    Pull through cache rules sync container image registries such as Amazon ECR Public, Quay and Docker Hub. npmjs.com is not a supported upstream.

  • BA Lambda layer that holds the npm packages, attached to the build project

    Incorrect

    Layers add code and dependencies to Lambda functions. They are not a package registry that npm can install from.

  • CA CodeArtifact repository whose upstream has an external connection to npmjs.com

    Correct

    With an external connection, CodeArtifact fetches public packages on request and stores them, and the build runs the CodeArtifact login command so npm uses the repository endpoint.

  • DA CodeArtifact repository without an external connection, filled by hand with public packages

    Incorrect

    This keeps one endpoint, but every public package would have to be published manually, which an external connection does on demand.

CodeArtifact serves private packages and caches public ones through an external connection, behind one endpoint that CodeBuild logs in to.

Question 4 · choose 1

A Python AWS Lambda function's .zip file archive has grown to 70 MB because of its dependencies. Its unzipped size is still within the quota. Uploading the archive from the developer's machine through the Lambda API now fails. How should the developer deploy the archive?

  1. ASplit the archive into two files and upload both to the function
  2. BUpload the archive to Amazon S3 and point the function's code to it
  3. CPaste the code into the console's embedded code editor
  4. DCompress the archive again with a higher compression level and retry
Show the answer and why
  • ASplit the archive into two files and upload both to the function

    Incorrect

    A function has one deployment package; splitting it does not create a second upload slot.

  • BUpload the archive to Amazon S3 and point the function's code to it

    Correct

    Archives larger than 50 MB must be uploaded from an Amazon S3 location instead of directly.

  • CPaste the code into the console's embedded code editor

    Incorrect

    The embedded editor is for small scripts; code with large libraries must be uploaded as an archive.

  • DCompress the archive again with a higher compression level and retry

    Incorrect

    Recompressing an archive of compressed libraries rarely saves much, and the direct upload limit stays the same.

Direct uploads of .zip archives are limited to 50 MB; larger archives go through Amazon S3, up to the unzipped size quota.

Question 5 · choose 1

In an AWS SAM project, a developer deploys a Python function that imports the requests library, which is listed in the function's requirements.txt. The deployed function fails with an import error because the library is missing from the package. Which step did the developer skip before sam deploy?

  1. Asam build, which prepares the code and its dependencies in .aws-sam
  2. Bsam validate, which checks the template for errors
  3. Csam local invoke, which runs the function once locally with a sample event
  4. Dsam logs, which shows the function's CloudWatch logs
Show the answer and why
  • Asam build, which prepares the code and its dependencies in .aws-sam

    Correct

    sam build creates the .aws-sam directory with the function code and the dependencies from its manifest file, ready to deploy.

  • Bsam validate, which checks the template for errors

    Incorrect

    Validation checks the template; it does not download or package dependencies.

  • Csam local invoke, which runs the function once locally with a sample event

    Incorrect

    Local invocation runs code for testing; it does not add libraries to the deployment package.

  • Dsam logs, which shows the function's CloudWatch logs

    Incorrect

    Logs show the error after the fact; they do not package dependencies.

Run sam build before deploying so that dependencies listed in manifest files are packaged with the code.

Question 6 · choose 1

A network team owns a CloudFormation stack that creates a VPC and its subnets. Several application stacks, owned by other teams and deployed separately, need the subnet IDs. The developer wants the application templates to get the IDs from the network stack without copying values by hand. What should the developer do?

  1. AHardcode the subnet IDs as default values of each application template's parameters
  2. BExport the subnet IDs as outputs and read them with Fn::ImportValue
  3. CUse Fn::GetAtt on the network stack's subnet resources by name
  4. DStore the template's Mappings section in the network stack
Show the answer and why
  • AHardcode the subnet IDs as default values of each application template's parameters

    Incorrect

    Hardcoded values must be copied by hand and go stale when the network stack changes.

  • BExport the subnet IDs as outputs and read them with Fn::ImportValue

    Correct

    Cross-stack references use the Export field of an output and the Fn::ImportValue function to read the value in another stack.

  • CUse Fn::GetAtt on the network stack's subnet resources by name

    Incorrect

    GetAtt reads attributes of resources in the same template, not of resources in another stack.

  • DStore the template's Mappings section in the network stack

    Incorrect

    Mappings are fixed values inside one template; they cannot hold the IDs that another stack creates.

Exports and Fn::ImportValue share values between independently deployed stacks.

Question 7 · choose 1

In an AWS SAM template, a function needs to read and write items in one DynamoDB table that the same template creates. The developer wants least privilege without writing a full IAM policy document by hand. What should the developer add to the function's Policies property?

  1. AThe AmazonDynamoDBFullAccess AWS managed policy
  2. BAn inline policy that allows dynamodb:* on all resources
  3. CThe DynamoDBCrudPolicy policy template with the table name
  4. DThe AdministratorAccess AWS managed policy for the deploy role
Show the answer and why
  • AThe AmazonDynamoDBFullAccess AWS managed policy

    Incorrect

    This managed policy grants access to all DynamoDB tables, far more than one table.

  • BAn inline policy that allows dynamodb:* on all resources

    Incorrect

    A wildcard on all resources is the opposite of least privilege.

  • CThe DynamoDBCrudPolicy policy template with the table name

    Correct

    SAM policy templates scope permissions to the resources your application uses, such as one table.

  • DThe AdministratorAccess AWS managed policy for the deploy role

    Incorrect

    Deployment permissions are separate from the function's permissions, and this grants far too much.

SAM policy templates give scoped permissions with little configuration.

Question 8 · choose 1

A team packages a Python AWS Lambda function as a container image. The image is built from a generic Python base image from a public registry, and Lambda cannot run it because nothing in the image talks to the Lambda runtime. What should the developer do?

  1. AUse an AWS base image for Lambda, or add the runtime interface client
  2. BPush the image to Docker Hub instead of Amazon ECR
  3. CRaise the function's memory so that the container can start
  4. DRepackage the code and libraries as a .zip file archive larger than 250 MB unzipped
Show the answer and why
  • AUse an AWS base image for Lambda, or add the runtime interface client

    Correct

    AWS base images include a runtime interface client; other base images need one added to work with Lambda.

  • BPush the image to Docker Hub instead of Amazon ECR

    Incorrect

    Lambda creates functions from images in Amazon ECR, and the registry is not what is missing.

  • CRaise the function's memory so that the container can start

    Incorrect

    Memory does not add the missing component that talks to the Lambda runtime.

  • DRepackage the code and libraries as a .zip file archive larger than 250 MB unzipped

    Incorrect

    The unzipped .zip deployment package is limited to 250 MB, so this is not possible.

Container images for Lambda need a runtime interface client; AWS base images include one.

Practise domain 3 →Practise all domains →