TL;DR
Certification earned
I organized these study notes around the official DVA-C02 domains, highlighting core serverless development patterns, security implementation, CI/CD deployment strategies, observability techniques, and practice questions.
Exam Overview and Domain Breakdown
The AWS Certified Developer – Associate (DVA-C02) exam covers four primary domains:
| Domain | Description | Exam Weighting |
|---|---|---|
| Domain 1 | Development with AWS Services | 32% |
| Domain 2 | Security | 26% |
| Domain 3 | Deployment | 24% |
| Domain 4 | Troubleshooting and Optimization | 18% |
The exam consists of 65 questions (50 scored questions and 15 unscored pretest questions). The time limit is 130 minutes, and the passing score is 720 out of 1000 on a scaled score.
Here is the study sequence I followed:
Domain 1: Development with AWS Services
This domain focuses on writing application code using AWS SDKs, building serverless applications with AWS Lambda, managing data stores like DynamoDB, and building decoupled event-driven architectures.
1. AWS Lambda Development & Lifecycle
- Execution Context Reuse: Instantiate database connections, HTTP clients, and heavy dependencies outside the function handler method so they persist across warm invocations.
- Concurrency Control:
- Reserved Concurrency: Guarantees a dedicated pool of concurrent executions and caps maximum concurrency to protect downstream databases.
- Provisioned Concurrency: Pre-warms execution environments to eliminate cold start latencies for latency-sensitive applications.
- VPC Integration: Connecting Lambda to private VPC resources creates Elastic Network Interfaces (ENIs). Ensure private subnets have adequate IP space and security groups.
- Event Source Models:
- Synchronous (API Gateway, ALB): Returns responses directly to the caller.
- Asynchronous (S3, SNS): Uses internal event queues with automatic 2-time retry policies before directing failed events to Dead-Letter Queues (DLQ) or Lambda Destinations.
- Stream/Poll-based (DynamoDB Streams, Kinesis): Processes records in batch sizes and requires error handling (e.g., bisect batch on error).
2. Amazon DynamoDB & Data Stores
- Partition Key Selection: Choose high-cardinality keys to distribute read/write traffic evenly across physical partitions and avoid hot keys.
- Query vs. Scan:
Query: Efficiently retrieves items matching a specific partition key (and optional sort key condition).Scan: Reads every item in the table; expensive and slow. Use Parallel Scans only when necessary, or filter usingQuery.
- Secondary Indexes:
- Local Secondary Index (LSI): Same partition key, alternate sort key. Must be created at table creation time.
- Global Secondary Index (GSI): Alternate partition key and sort key. Can be created or deleted anytime.
- Caching & Consistent Reads:
- Eventually Consistent Reads (Default): Consumes 0.5 Read Capacity Units (RCU) per 4 KB.
- Strongly Consistent Reads: Consumes 1 RCU per 4 KB.
- ElastiCache (Redis OSS): Ideal for relational (RDS) or general application-level caching using Write-Through strategies to ensure zero stale reads.
- DynamoDB Accelerator (DAX): Microsecond in-memory cache specifically designed for DynamoDB.
3. Event-Driven Messaging & AI Assistance
- Fanout Architecture: Connect an Amazon SNS topic to multiple Amazon SQS queues so multiple independent services receive every event durably.
- Change Data Capture: Enable DynamoDB Streams to stream record modifications and trigger Lambda functions for downstream processing or external API notifications.
- AI-Assisted Coding: Use Amazon Q Developer to assist with inline code completion, spec-driven code generation, automated test suite creation, and security scanning.
Domain 1 Practice Questions
Question 1
A developer needs to execute an external API call every time an item in an Amazon DynamoDB table is created or modified. The solution must scale automatically. Which combination of steps fulfills this requirement? (Select TWO)
- A. Enable DynamoDB Streams on the table
- B. Configure an Amazon EventBridge rule that listens directly to table changes
- C. Create an AWS Lambda function triggered by the DynamoDB stream to call the external API
- D. Configure an SQS queue to poll the DynamoDB table directly
- E. Publish table updates directly to an SNS topic without intermediate compute
Show answer and reason
Answer: A and C.
Reason: DynamoDB Streams captures item-level change data (insert, modify, delete) in real time. Configuring a Lambda function with a DynamoDB stream event source mapping allows automated execution of custom business logic or external API calls whenever table records change.
Question 2
A high-traffic Java application running on AWS Lambda connects to an Amazon RDS MySQL database. During load testing, performance degrades due to the creation of new database connections on every invocation. How should the developer resolve this issue?
- A. Increase the Lambda function memory allocation to speed up database connection handshakes
- B. Store the database connection credentials in Lambda environment variables
- C. Initialize the database connection object outside the Lambda handler method
- D. Place the database connection string inside a local JSON file inside the deployment package
Show answer and reason
Answer: C. Initialize the database connection object outside the Lambda handler method.
Reason: Code outside the handler method runs during the initialization phase of the execution environment. Subsequent warm invocations reuse this execution context, including initialized database connection pools, avoiding connection setup latency.
Question 3
An application backed by an Amazon RDS database requires extremely fast read performance for unpredictable traffic spikes. The application cannot tolerate reading stale data under any circumstances. Which caching strategy satisfies these criteria?
- A. Deploy an Amazon DynamoDB Accelerator (DAX) cluster in front of RDS
- B. Create an Amazon RDS Read Replica and route read queries to it
- C. Implement an Amazon ElastiCache cluster using a write-through caching strategy
- D. Enable Multi-AZ standby replica reading on the RDS instance
Show answer and reason
Answer: C. Implement an Amazon ElastiCache cluster using a write-through caching strategy.
Reason: A write-through cache updates the ElastiCache cluster synchronously whenever data is written to the underlying database, guaranteeing that subsequent cache reads return up-to-date data. Read Replicas rely on asynchronous replication, which introduces replication lag and potential stale reads.
Domain 2: Security
This domain tests your understanding of authentication, fine-grained access authorization, encryption in transit and at rest, and secret management patterns.
1. Identity & Access Management
- IAM Roles vs. Access Keys: Never hardcode access keys in source code. EC2 instances use instance profiles, and Lambda functions use execution roles.
- AWS STS (Security Token Service): Call
AssumeRoleto retrieve temporary credentials across accounts or for temporary access elevated privileges. - Amazon Cognito:
- User Pools: Handles authentication (user registration, login, MFA, social identity federation) and issues JWT tokens (ID Token, Access Token, Refresh Token).
- Identity Pools (Federated Identities): Provides authorization by exchanging JWTs or third-party identity tokens for temporary AWS IAM credentials to access AWS resources directly.
2. Encryption & Key Management
- Client-Side vs. Server-Side Encryption:
- Server-Side Encryption (SSE): AWS encrypts data at rest after receiving it (e.g., SSE-S3, SSE-KMS, SSE-C).
- Client-Side Encryption: Data is encrypted on the client side before sending it across the network to AWS using libraries like the AWS Database Encryption SDK.
- AWS KMS Key Types:
- Symmetric Keys: Used for single-key encryption/decryption operations and envelope encryption (Data Encryption Keys).
- Asymmetric Keys: RSA/ECC key pairs used when signing or encrypting outside of AWS without revealing private keys.
3. Secret & Sensitive Data Management
| Service | Rotation | Security & Features |
|---|---|---|
| AWS Systems Manager Parameter Store | Manual / Custom EventBridge | Stores strings, list parameters, and SecureString (KMS encrypted). Free tier available for standard parameters. |
| AWS Secrets Manager | Native Automatic Rotation (via built-in or custom Lambda) | Specifically designed for sensitive secrets (DB credentials, API keys). Cross-account sharing and automatic rotation scheduling. |
Domain 2 Practice Questions
Question 1
A company requires client-side encryption of sensitive attributes before writing data into an Amazon DynamoDB table. The encrypted data must remain protected end-to-end in transit and at rest. Which cryptographic combination meets these requirements? (Select TWO)
- A. Use generated symmetric encryption keys with AWS KMS
- B. Enable DynamoDB default table encryption with AWS owned keys
- C. Use the AWS Database Encryption SDK within the application code
- D. Generate asymmetric encryption keys with AWS KMS
- E. Enable server-side encryption with AWS managed KMS keys (SSE-KMS)
Show answer and reason
Answer: A and C.
Reason: Client-side item attribute encryption is accomplished using the AWS Database Encryption SDK prior to transmitting data to DynamoDB. When configured with AWS KMS, the SDK requires a symmetric KMS key to generate unique data encryption keys for each table item.
Question 2
A Python application running on an EC2 instance attempts to query a DynamoDB table. The application receives the error: An error occurred (AccessDenied) when calling the operation. The instance is attached to an IAM role named ec2-app-role. How should the developer fix this issue?
- A. Run
aws configureon the EC2 instance and input the IAM root user’s credentials - B. Create a new IAM policy with
dynamodb:Querypermissions and attach it toec2-app-role - C. Attach a second IAM role with DynamoDB access permissions to the EC2 instance
- D. Run
aws sts assume-rolelocally and hardcode the session key into the application script
Show answer and reason
Answer: B. Create a new IAM policy with dynamodb:Query permissions and attach it to ec2-app-role.
Reason: An AccessDenied error indicates an authorization issue. An EC2 instance profile can only assume one IAM role at a time, so permissions must be granted by attaching an IAM policy containing the required DynamoDB actions directly to the instance’s role.
Question 3
A developer needs to store a third-party API key that a Lambda function uses to call an external service. The third party enforces automatic API key rotation every 4 months via basic authentication endpoints. Which storage strategy automates this process securely with minimal maintenance?
- A. Store the API key inside a Lambda environment variable and update it manually
- B. Store the API key in AWS Secrets Manager and configure automated rotation using a custom Lambda rotation function
- C. Store the API key in AWS Systems Manager Parameter Store as a
SecureStringand schedule an EventBridge cron rule - D. Hardcode the API key in an encrypted configuration file bundled in the Java deployment ZIP package
Show answer and reason
Answer: B. Store the API key in AWS Secrets Manager and configure automated rotation using a custom Lambda rotation function.
Reason: AWS Secrets Manager supports automated secret rotation lifecycles out-of-the-box. When integrated with a custom rotation Lambda function, Secrets Manager can invoke the third-party basic auth endpoint, retrieve the updated key, and update the secret store seamlessly without downtime.
Domain 3: Deployment
This domain covers preparing build artifacts, defining Infrastructure as Code (IaC) templates, configuring API Gateway integrations, and automating continuous delivery pipelines.
1. Infrastructure as Code (IaC) & Packaging
- AWS Serverless Application Model (AWS SAM):
- Extension of CloudFormation designed for serverless application resources (
AWS::Serverless::Function,AWS::Serverless::Api,AWS::Serverless::SimpleTable). - Essential SAM CLI Commands:
sam build,sam local invoke,sam package,sam deploy.
- Extension of CloudFormation designed for serverless application resources (
- AWS AppConfig: Manages, validates, and deploys application configurations dynamically at runtime without requiring application re-deployments or server restarts.
2. Amazon API Gateway Configurations
- Integration Types:
- Lambda Proxy Integration (Recommended): API Gateway passes the entire raw HTTP request (headers, query params, body) as a JSON object directly to the Lambda event handler.
- Lambda Custom Integration: Requires Request/Response VTL transformation mapping templates.
- Stage Variables: Dynamic variables defined per API stage (e.g.,
dev,test,prod). Accessing stage variables in Lambda integration URIs is formatted as:${stageVariables.variableName}
3. CI/CD Tools & Deployment Strategies
- AWS Developer Tools Overview:
- AWS CodeBuild: Runs build and test scripts defined in a
buildspec.ymlfile. - AWS CodeDeploy: Controls code deployment onto EC2, ECS, or Lambda target environments based on instructions in an
appspec.ymlfile. - AWS CodePipeline: Orchestrates the multi-stage CI/CD workflow from source repository to final production release.
- AWS CodeBuild: Runs build and test scripts defined in a
- Deployment Strategies:
- Canary: Shift a small percentage of traffic to the new version, monitor it, then route the remaining traffic.
- Linear: Increase traffic to the new version in equal increments over time.
- Blue/Green: Switch traffic from the old environment to the new environment after validation.
The deployment strategies can be summarized as follows:
Canary: [10% traffic] -- (wait) --> [100% traffic]
Linear: [10%] -> [20%] -> ... -> [100%]
Blue/Green: [old version] === switch ===> [new version]
Domain 3 Practice Questions
Question 1
A developer configures AWS CodeDeploy to deploy an application to Amazon EC2 instances managed by an Auto Scaling group. Where must the developer place the appspec.yml file in the source repository?
- A. In the
.ebextensionsconfiguration directory - B. Directly uploaded into the CodeDeploy service console settings
- C. At the root directory of the application source code bundle
- D. In an Amazon S3 bucket root alongside the deployment artifact zip file
Show answer and reason
Answer: C. At the root directory of the application source code bundle.
Reason: For CodeDeploy deployments to EC2 or on-premises instances, the appspec.yml manifest file must always reside at the root of the application’s source directory structure.
Question 2
A company is migrating its API backend to Amazon API Gateway and AWS Lambda. The application supports production, testing, and development environments. The company wants to route API requests dynamically using a single API Gateway endpoint based on stage configurations. How should this be configured?
- A. Append
${stageVariables.LambdaAlias}to the Lambda function ARN in the API Gateway proxy route, and set stage variables on each stage - B. Define separate custom domain names for each environment without using API Gateway stage settings
- C. Store alias strings inside Lambda environment variables and reference them inside the API Gateway route definition
- D. Modify the Lambda execution role to allow
apigateway:*cross-account access
Show answer and reason
Answer: A. Append ${stageVariables.LambdaAlias} to the Lambda function ARN in the API Gateway proxy route, and set stage variables on each stage.
Reason: API Gateway Stage Variables allow developers to configure dynamic endpoints. Referencing ${stageVariables.variableName} in the Lambda invocation ARN directs traffic dynamically to the correct target Lambda Alias (e.g., production, testing, development).
Question 3
An image processing workflow requires sending upload notifications from Amazon S3 to five distinct backend services simultaneously. Each service operates independently, and processing must not be lost if a service is temporarily offline. Which architectural pattern satisfies this requirement?
- A. S3 Event Notifications publishing directly to a single Amazon SQS queue polled by all 5 services
- B. S3 Event Notifications publishing to an Amazon SNS topic, with 5 individual Amazon SQS queues subscribed to the topic
- C. S3 Event Notifications invoking 5 individual synchronous Lambda functions directly
- D. S3 Event Notifications publishing to Amazon Kinesis Data Firehose attached to an S3 archive
Show answer and reason
Answer: B. S3 Event Notifications publishing to an Amazon SNS topic, with 5 individual Amazon SQS queues subscribed to the topic.
Reason: This implements the SNS-to-SQS Fanout design pattern. SNS distributes the single S3 event to all subscribed queues. Because each microservice consumes from its dedicated SQS queue, messages remain safely buffered if a service goes down temporarily.
Domain 4: Troubleshooting and Optimization
This domain focuses on instrumenting code for observability, debugging microservices using distributed tracing, analyzing application metrics, and optimizing resource performance.
1. Distributed Tracing with AWS X-Ray
- Service Map: Visualizes node graphs of application microservices, downstream HTTP calls, and AWS resources to isolate latency bottlenecks and fault origins.
- Traces, Segments, and Subsegments:
- Segment: Documents computing node activity (e.g., EC2, Lambda).
- Subsegment: Documents detailed sub-operations (e.g., outbound downstream HTTP requests, SQL queries, DynamoDB calls).
- Annotations vs. Metadata:
- Annotations: Indexed key-value pairs used for filtering traces in the X-Ray console (e.g.,
FilterExpression: "User = 'Nabil'"). - Metadata: Non-indexed key-value pairs containing detailed data objects or debug payloads.
- Annotations: Indexed key-value pairs used for filtering traces in the X-Ray console (e.g.,
2. Metrics, Logging, and Observability
- CloudWatch Logs Insights: Interactive log query tool used to parse, filter, and analyze structured JSON logs across log groups.
- CloudWatch Embedded Metric Format (EMF): Formats structured logs as JSON payloads that CloudWatch automatically extracts into high-cardinality metrics asynchronously, preventing performance overhead from blocking synchronous HTTP calls.
- Application Health: Create custom health checks, readiness probes, and CloudWatch Alarms attached to SNS topic alerts.
3. Error Handling & Refactoring
- Exponential Backoff with Jitter: When handling transient errors or API rate throttling (
ProvisionedThroughputExceededException), retry API calls exponentially with random sleep delays (jitter) to prevent thundering herd problems. - Lambda Logging Permissions: Lambda functions require execution role permissions (
logs:CreateLogGroup,logs:CreateLogStream,logs:PutLogEvents) provided by theAWSLambdaBasicExecutionRolepolicy to generate output in CloudWatch Logs.
Domain 4 Practice Questions
Question 1
An e-commerce backend consists of over 20 microservices behind Amazon API Gateway. Users report intermittent slowdowns, but logs are spread across multiple systems. Which AWS service provides a visual service map to identify the exact service causing high latency?
- A. AWS CloudTrail
- B. Amazon CloudWatch Logs Insights
- C. AWS X-Ray
- D. AWS Trusted Advisor
Show answer and reason
Answer: C. AWS X-Ray.
Reason: AWS X-Ray collects trace header context across microservices, generating a visual Service Map that pinpoints specific latency bottlenecks, response durations, and failure points within distributed systems.
Question 2
A tablet-based worker application serves as an activity task worker for an AWS Step Functions workflow. Occasionally, tablets lose battery power while processing long tasks. The workflow must re-assign stalled tasks to another worker within 30 seconds, and fail the step after 3 retries. Which task configuration fulfills this demand?
- A. Set
TimeoutSecondsto 30 andRetry.MaxAttemptsto 3 - B. Set
HeartbeatSecondsto 30 andRetry.MaxAttemptsto 3 - C. Set state machine
States.Timeoutto 30 andRetry.BackoffRateto 3 - D. Set state machine
States.TaskFailedto 30 seconds
Show answer and reason
Answer: B. Set HeartbeatSeconds to 30 and Retry.MaxAttempts to 3.
Reason: The HeartbeatSeconds parameter requires the worker to send heartbeat signals continuously. If a tablet powers off, Step Functions detects missing heartbeats after 30 seconds and raises a States.Timeout error, triggering the Retry block to assign the task to another worker up to 3 times.
Question 3
A developer is writing a Python Lambda function that uses print() statements to output debugging information. When testing the function, the function runs successfully, but no execution log output appears in CloudWatch Logs. What is the cause of this issue?
- A. Print statements in Python write to
stdout, which is ignored by CloudWatch Logs - B. Lambda logging is disabled by default in the AWS Lambda console settings
- C. The Lambda execution role lacks the
logs:PutLogEventsIAM permission - D. Python functions must explicitly export logs to an S3 bucket destination
Show answer and reason
Answer: C. The Lambda execution role lacks the logs:PutLogEvents IAM permission.
Reason: Lambda automatically captures stdout and stderr output streams. However, for Lambda to write those log streams into CloudWatch Logs, its assigned execution role must contain the AWSLambdaBasicExecutionRole managed policy or explicit CloudWatch Logs permissions.
Five Scenario Questions for Final Review
Scenario 1: Multi-Device Session Storage
Users of a web application running on an EC2 Auto Scaling group behind an Application Load Balancer (ALB) report that session data is lost when switching between smartphones and laptops. Which state management redesign solves this issue?
- A. Enable ALB sticky sessions (session affinity)
- B. Save session state in local web server storage files on EC2
- C. Offload and store user session state in an Amazon ElastiCache (Redis OSS) cluster
- D. Store session state data using AWS Systems Manager State Manager
Show answer and reason
Answer: C. Offload and store user session state in an Amazon ElastiCache (Redis OSS) cluster.
Explanation: ALB sticky sessions rely on client-side cookies tied to a single device. Storing session state in a centralized, in-memory cache like ElastiCache Redis decouples state from instance hardware, making session data accessible across any device.
Scenario 2: Programmatic Credentials for Local Development
A developer running a Boto3 Python script on a local laptop receives an InvalidAccessKeyId error when attempting to access AWS services. The .aws/credentials file contains the developer’s console IAM username and password. What adjustment is required?
- A. Move the IAM username and password to environment variables
- B. Replace the IAM username and password with a valid Access Key ID and Secret Access Key
- C. Move the IAM username and password to the
.aws/configfile - D. Add the IAM Role ARN into the
AWS_PROFILEvariable
Show answer and reason
Answer: B. Replace the IAM username and password with a valid Access Key ID and Secret Access Key.
Explanation: AWS SDKs require programmatic access credentials (Access Key ID and Secret Access Key). Console login credentials (usernames and passwords) cannot authenticate programmatic API requests.
Scenario 3: Serverless Alias Management
A development team needs to deploy new Lambda code updates without affecting existing production callers. How should versions and aliases be configured?
- A. Point the
Productionalias to a published numerical Lambda version, and point theDevelopmentalias to the$LATESTversion - B. Create a new Lambda layer every time code changes need testing
- C. Point the
Productionalias to a Lambda layer ARN - D. Point the
Productionalias to theDevelopmentalias directly
Show answer and reason
Answer: A. Point the Production alias to a published numerical Lambda version, and point the Development alias to the $LATEST version.
Explanation: Lambda function versions are immutable snapshots of code and configuration. Aliases act as named pointers to versions, allowing production clients to call a stable version while development testing occurs on $LATEST.
Scenario 4: Step Functions Activity Polling API Actions
Which sequence of Step Functions API calls must a custom task worker running on an external server execute to register, fetch work, maintain state, and return execution results?
- A.
StartExecution,GetActivityTask,SendTaskHeartbeat,StopExecution - B.
CreateActivity,GetActivityTask,SendTaskHeartbeat,SendTaskSuccess(orSendTaskFailure) - C.
CreateActivity,SendTaskHeartbeat,DeleteActivity - D.
StartExecution,SendTaskHeartbeat,SendTaskSuccess
Show answer and reason
Answer: B. CreateActivity, GetActivityTask, SendTaskHeartbeat, SendTaskSuccess (or SendTaskFailure).
Explanation: Activity task workers call CreateActivity to register an activity, poll for tasks using GetActivityTask, periodically send progress updates with SendTaskHeartbeat, and finalize tasks using SendTaskSuccess or SendTaskFailure.
Scenario 5: SDK IAM Role Permission Denial
An application hosted on an EC2 instance attempts to write items to DynamoDB, but receives AccessDenied. The instance has an IAM Role attached named AppDBRole. How should this authorization failure be remediated?
- A. Query the instance metadata service to retrieve session keys and run
aws configure - B. Attach a new IAM policy containing
dynamodb:PutItempermissions toAppDBRole - C. Attach a second IAM role to the EC2 instance profile
- D. Run
aws sts assume-roleusing theAppDBRoleARN inside the code
Show answer and reason
Answer: B. Attach a new IAM policy containing dynamodb:PutItem permissions to AppDBRole.
Explanation: AccessDenied indicates that the request was authenticated using the EC2 instance profile’s role, but the role lacks the specific IAM permission statement for the requested DynamoDB operation. Adding an IAM policy with the required action permissions to the existing role resolves the issue.
Final Thoughts
Preparing for the DVA-C02 exam requires moving beyond high-level service concepts into hands-on SDK implementation mechanics, security policies, and application deployment patterns.
My advice