Skip to content
BytePatterns

DVA-C02 · Domain 3: Deployment · 24% of the exam

Task 3.3: Automate deployment testing

Making tests part of every deployment: test events and payloads, deploying APIs to each environment, Lambda aliases and image tags that pin approved versions, infrastructure as code with AWS SAM and CloudFormation, and generating tests with Amazon Q Developer.

Study it

  • AWS SAM: templates, local testing and deploying to another environment

    Lesson coming

  • Test events, integration tests and mocks

    Lesson coming

  • API Gateway stages, stage variables and custom domains

    Lesson coming

  • Lambda versions and aliases for approved releases

    Lesson coming

  • CloudFormation and the CDK: templates, change sets and updates

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

An AWS Lambda function in an AWS SAM project processes messages from an Amazon SQS queue. In the continuous integration build, before anything is deployed, the developer wants to run the function locally with a realistic SQS event payload without writing the JSON structure by hand. What should the developer do?

  1. ASave a private test event in the Lambda console and run it from the build
  2. BCreate a real queue, send messages to it, and let the event source mapping invoke the function
  3. CRun sam local start-api and send the message body to it with an HTTP client
  4. DGenerate a payload with sam local generate-event sqs and pass it to sam local invoke --event
Show the answer and why
  • ASave a private test event in the Lambda console and run it from the build

    Incorrect

    Console test events run against the deployed function, and a private test event is available only to the user who created it.

  • BCreate a real queue, send messages to it, and let the event source mapping invoke the function

    Incorrect

    That tests a deployed function with real AWS resources, which the build wants to avoid at this stage.

  • CRun sam local start-api and send the message body to it with an HTTP client

    Incorrect

    sam local start-api serves functions through a local HTTP server. The function would receive an HTTP request event, not an SQS event.

  • DGenerate a payload with sam local generate-event sqs and pass it to sam local invoke --event

    Correct

    sam local generate-event produces sample payloads for supported services, which can be edited and passed with --event to a local invocation.

SAM CLI generates realistic service events for local tests: generate-event for the payload, local invoke to run the function with it.

Question 2 · choose 1

Developers deploy new code for an AWS Lambda function several times a day. An integration test environment must always call the function code that QA last approved, not whatever was deployed most recently. QA wants to promote a new approved build by changing one setting, without updating every service that calls the function. What should the developer set up?

  1. AHave the test environment invoke $LATEST, where every deployment lands
  2. BHave every caller use the ARN of the approved numbered version, edited on each promotion
  3. CPublish versions and point a test alias at the approved one; callers use the alias ARN
  4. DTurn on provisioned concurrency for $LATEST so that tested code stays loaded
Show the answer and why
  • AHave the test environment invoke $LATEST, where every deployment lands

    Incorrect

    Every code deployment overwrites $LATEST, so the tests would run whatever was deployed last instead of the approved build.

  • BHave every caller use the ARN of the approved numbered version, edited on each promotion

    Incorrect

    A published version is an immutable snapshot, so this pins approved code, but each promotion means changing every caller.

  • CPublish versions and point a test alias at the approved one; callers use the alias ARN

    Correct

    An alias is a pointer to a function version that can be updated. QA promotes a build by moving the alias, and callers keep the same alias ARN.

  • DTurn on provisioned concurrency for $LATEST so that tested code stays loaded

    Incorrect

    Provisioned concurrency cannot be used with $LATEST, and it only keeps environments initialized; it does not pin a version.

Versions freeze code and configuration; aliases give callers a stable name that can be moved to the approved version.

Question 3 · choose 2

A REST API in Amazon API Gateway has a dev stage and a prod stage. Its GET /quote method uses a Lambda integration. Calls through the dev stage must invoke the dev alias of the quote function, and calls through the prod stage must invoke the prod alias, with one method definition shared by both stages. Which TWO steps should the developer take? (Choose TWO.)

  1. ASet the function to quote:${stageVariables.alias} and define alias in each stage
  2. BAdd a canary setting on the prod stage that sends all of its traffic to the prod alias
  3. CCreate a usage plan for each stage with its own throttling limits
  4. DRun lambda add-permission so API Gateway may invoke each alias used by the stages
  5. ETurn on API caching in each stage so that each alias has its own cache
Show the answer and why
  • ASet the function to quote:${stageVariables.alias} and define alias in each stage

    Correct

    A stage variable can supply the function name, including an alias such as quote:prod, so each stage resolves the same method to its own alias.

  • BAdd a canary setting on the prod stage that sends all of its traffic to the prod alias

    Incorrect

    A canary splits one stage's traffic at random between a production deployment and a canary deployment. It does not map stages to aliases.

  • CCreate a usage plan for each stage with its own throttling limits

    Incorrect

    Usage plans give clients access to stages with throttling and quotas. They do not decide which backend a method calls.

  • DRun lambda add-permission so API Gateway may invoke each alias used by the stages

    Correct

    When a stage variable names the function, the permissions on the Lambda function must be configured manually, for example with add-permission.

  • ETurn on API caching in each stage so that each alias has its own cache

    Incorrect

    Caching stores endpoint responses for a TTL. It does not choose which function or alias the integration calls.

Stage variables make one API definition behave per environment; when they name a Lambda function or alias, API Gateway also needs an invoke permission on each target.

Question 4 · choose 1

A developer inherited a Java service class with no tests. The team wants unit tests for it, including edge cases, that can run in the AWS CodeBuild project on every commit. The developer wants help writing the tests from within the IDE. Which approach fits best?

  1. AAsk Amazon Q Developer in the IDE chat to generate unit tests for the class
  2. BTurn on AWS X-Ray for the service and convert its traces into test cases
  3. CRun sam local generate-event to produce the unit tests for the class
  4. DRun an Amazon Q Developer code transformation on the project
Show the answer and why
  • AAsk Amazon Q Developer in the IDE chat to generate unit tests for the class

    Correct

    Amazon Q Developer in the IDE can generate unit tests, so the developer can review them and add them to the build.

  • BTurn on AWS X-Ray for the service and convert its traces into test cases

    Incorrect

    X-Ray collects and analyzes data about the requests an application serves. It does not produce unit tests.

  • CRun sam local generate-event to produce the unit tests for the class

    Incorrect

    sam local generate-event creates sample event payloads for AWS services. It does not write unit tests for application classes.

  • DRun an Amazon Q Developer code transformation on the project

    Incorrect

    Code transformation upgrades and migrates applications, such as Java version upgrades. Generating unit tests is a different capability.

Amazon Q Developer can generate unit tests in the IDE; the developer reviews them and runs them in the pipeline like any other tests.

Question 5 · choose 1

AWS CodeDeploy shifts traffic to new versions of an AWS Lambda function. After all traffic has moved to the new version, the team wants an automated smoke test function to run end-to-end checks, and a failure must roll the deployment back. Which AppSpec hook should run the test function?

  1. ABeforeInstall
  2. BBeforeAllowTraffic
  3. CAfterAllowTraffic
  4. DValidateService
Show the answer and why
  • ABeforeInstall

    Incorrect

    BeforeInstall is a hook for EC2, on-premises and Amazon ECS deployments, not for Lambda version deployments.

  • BBeforeAllowTraffic

    Incorrect

    BeforeAllowTraffic runs before traffic is shifted, not after the new version serves all traffic.

  • CAfterAllowTraffic

    Correct

    AfterAllowTraffic runs after all traffic is shifted to the new version, and a failing hook function can trigger a rollback.

  • DValidateService

    Incorrect

    ValidateService belongs to EC2 and on-premises deployments; Lambda deployments use the AllowTraffic hooks.

Lambda deployments with CodeDeploy have two hooks: BeforeAllowTraffic and AfterAllowTraffic.

Question 6 · choose 1

In an AWS CodePipeline V2 pipeline, the Deploy stage is followed by automated tests in the same stage. When the tests fail, the team wants the stage to go back automatically to the last execution that succeeded in it, instead of someone redeploying by hand. What should the developer configure?

  1. AAutomatic rollback on failure for the stage
  2. BThe PARALLEL execution mode for the pipeline
  3. CA manual approval action after the tests
  4. DA retry of the failed stage after each failure
Show the answer and why
  • AAutomatic rollback on failure for the stage

    Correct

    A stage can be preconfigured to roll back on failure to an execution that succeeded in that stage.

  • BThe PARALLEL execution mode for the pipeline

    Incorrect

    In PARALLEL mode stage rollback is not available, so this works against the goal.

  • CA manual approval action after the tests

    Incorrect

    An approval waits for a person and does not roll anything back.

  • DA retry of the failed stage after each failure

    Incorrect

    A retry runs the same failing revision again; it does not return to the last good one.

CodePipeline stage rollback returns a stage to a previously successful execution, automatically on failure if configured.

Question 7 · choose 1

A pipeline in AWS CodePipeline must run a custom check after deployment: an AWS Lambda function calls the new API and compares the results with expected values. The pipeline must continue only if the check passes. How should the function report its result to the pipeline?

  1. AReturn HTTP status 200 or 500 from the function handler
  2. BWrite a file named result.txt to the pipeline's artifact bucket
  3. CPublish a message to an Amazon SNS topic that the pipeline watches
  4. DCall PutJobSuccessResult or PutJobFailureResult with the job ID
Show the answer and why
  • AReturn HTTP status 200 or 500 from the function handler

    Incorrect

    CodePipeline does not read the handler's return value as an HTTP status; the job result must be reported through the API.

  • BWrite a file named result.txt to the pipeline's artifact bucket

    Incorrect

    A file in the artifact bucket is not how a Lambda action tells the pipeline that its job succeeded or failed.

  • CPublish a message to an Amazon SNS topic that the pipeline watches

    Incorrect

    Pipelines do not subscribe to SNS topics to complete Lambda invoke actions.

  • DCall PutJobSuccessResult or PutJobFailureResult with the job ID

    Correct

    The Lambda invoke action passes a job ID in its event, and the function reports the outcome with the job result API operations.

Lambda invoke actions are job workers: they receive a job ID and must report success or failure for it.

Question 8 · choose 1

A small team deploys AWS Lambda functions with the AWS CLI and no deployment service. For the next release, it wants 5 percent of production invocations to go to the new version while it watches metrics, with a quick way to move all traffic back. What should the developer do?

  1. APoint the prod alias at the new version and keep the old version's ARN
  2. BConfigure the prod alias with weighted routing between the two versions
  3. CSet reserved concurrency of 5 on the new version
  4. DCreate a second function and call it from the first in 5 percent of requests
Show the answer and why
  • APoint the prod alias at the new version and keep the old version's ARN

    Incorrect

    This sends all traffic to the new version at once, not 5 percent.

  • BConfigure the prod alias with weighted routing between the two versions

    Correct

    A weighted alias splits traffic between two versions, so a small share can test the new version and be rolled back quickly.

  • CSet reserved concurrency of 5 on the new version

    Incorrect

    Reserved concurrency is set on the function, not per version, and does not split traffic by percentage.

  • DCreate a second function and call it from the first in 5 percent of requests

    Incorrect

    Hand-written routing in code duplicates what alias routing provides.

Weighted aliases give simple canary releases for Lambda without extra services.

Question 9 · choose 1

A Java project's tests run in AWS CodeBuild and write a JaCoCo XML coverage file. The team wants line and branch coverage for each build shown in CodeBuild, so that coverage drops are visible without another tool. What should the developer configure?

  1. AA coverage report for the JaCoCo file in the buildspec reports section
  2. BAn artifacts entry that uploads the JaCoCo file to Amazon S3 after each build
  3. CA CloudWatch Logs metric filter on the build log
  4. DA local cache entry for the JaCoCo file
Show the answer and why
  • AA coverage report for the JaCoCo file in the buildspec reports section

    Correct

    CodeBuild can generate code coverage reports from formats such as JaCoCo XML, including line and branch coverage.

  • BAn artifacts entry that uploads the JaCoCo file to Amazon S3 after each build

    Incorrect

    Artifacts store files; CodeBuild does not show coverage from them.

  • CA CloudWatch Logs metric filter on the build log

    Incorrect

    A metric filter needs coverage values printed as log text and builds a separate view, which the team wants to avoid.

  • DA local cache entry for the JaCoCo file

    Incorrect

    Caching reuses files between builds; it does not create reports.

CodeBuild report groups cover both test reports and code coverage reports.

Practise domain 3 →Practise all domains →