41 practice questions for Domain 2 of the AWS Certified Developer - Associate (DVA-C02) exam, which makes up 26% of its scored content. Your answers count towards one score and one timer for the whole exam.
Domain 2: Security
50. A mobile application must let users sign in with a social identity provider and then upload only to their own Amazon S3 prefix. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: B, E. The user pool federates the sign-in, and the identity pool exchanges the token for temporary credentials whose policy can use a variable such as the Cognito identity ID to confine each user to their own prefix. An IAM user per mobile user does not scale and needs long-term keys. An embedded shared key can be extracted from any installed application. An API key identifies a caller for throttling and is not authentication.
51. An Amazon API Gateway REST API must authenticate users from an Amazon Cognito user pool without any custom authorization code. Which solution meets these requirements?
Answer and explanation
Answer: C. API Gateway integrates natively with Cognito user pools, validating the token and its claims before invoking the backend with no code to maintain. A Lambda authorizer would work but is custom code. API keys identify a caller for usage plans and are not authentication. A permissive resource policy grants access rather than restricting it.
52. An application must give a specific external AWS account permission to invoke an AWS Lambda function directly. Which solution meets these requirements?
Answer and explanation
Answer: B. A resource-based policy on the function is how cross-account invoke permission is granted. An identity policy in the owning account cannot by itself grant permissions to a principal in another account. Lambda functions do not take security groups for invocation control. API keys apply to API Gateway usage plans.
53. An Amazon CloudFront distribution must serve private content so that authenticated users can retrieve many files under one path, with access expiring after 15 minutes. Which solution meets these requirements?
Answer and explanation
Answer: D. Signed cookies grant time-limited access to a set of objects matching a path pattern, which suits protecting many files without generating a URL for each. Signed URLs work but require one per object. IP restriction does not identify users. Origin Access Control restricts origin access to the distribution but does not authenticate end users.
54. An application running in a VPC must call Amazon DynamoDB without traversing the internet and without incurring an hourly endpoint charge. Which solution meets these requirements?
Answer and explanation
Answer: C. Gateway endpoints for Amazon S3 and DynamoDB add a route through the AWS network at no hourly charge. Interface endpoints carry an hourly cost and are used for services without gateway support. A NAT gateway routes to the internet and bills hourly plus data processing. An internet gateway provides the public path the requirement excludes.
55. A single IAM policy must grant each user access only to their own prefix in an Amazon S3 bucket. Which solution meets these requirements?
Answer and explanation
Answer: A. Policy variables substitute request context at evaluation time, so one statement scopes each caller to their own prefix. A statement per user does not scale. A permissions boundary caps maximum permissions rather than scoping resources per user. A service control policy restricts accounts and cannot express per-user prefixes.
56. An AWS Lambda function's execution role currently allows dynamodb:* on all tables. Which solution applies least privilege?
Answer and explanation
Answer: A. Least privilege means naming the actions the function actually performs and the exact resources, including index ARNs when the function queries them. A boundary permitting the same broad action narrows nothing. Running in a VPC changes networking rather than permissions. CloudTrail records activity without restricting it.
57. An Amazon API Gateway endpoint must be protected against SQL injection and other common web exploits. Which solution meets these requirements?
Answer and explanation
Answer: C. WAF inspects requests against managed rules covering injection and other common exploit patterns. Request validation checks structure against a schema but does not detect malicious payload content. API keys identify callers for usage plans. Detailed metrics improve observability without filtering requests.
58. An application on Amazon ECS with the AWS Fargate launch type must call Amazon S3 and Amazon DynamoDB. Which solution meets these requirements?
Answer and explanation
Answer: D. A task role delivers temporary, automatically rotated credentials scoped to that task, which is the least-privilege mechanism for containers. Keys in an image are exposed to anyone who pulls it. Environment variables holding long-term credentials leak through logs and console output. Fargate exposes no customer-visible host, so there is no instance profile to attach.
59. A REST API must accept requests only from a specific web origin and reject browser calls made from other sites. Which solution meets these requirements?
Answer and explanation
Answer: C. CORS configuration tells the browser which origins may make cross-origin calls, and naming a single origin causes browsers to block calls from other sites. A wildcard removes the restriction. An API key embedded in a web application is visible to anyone inspecting the client. A permissive resource policy grants access rather than restricting it.
60. An application in Account A must read a DynamoDB table in Account B. Which solution meets these requirements?
Answer and explanation
Answer: C. A cross-account role with a trust policy naming Account A issues temporary credentials on assumption, which is the standard auditable pattern. Sharing long-term keys across accounts removes attribution and requires manual rotation. Anonymous access exposes the table publicly. VPC peering provides network connectivity and grants no API permissions.
61. An Amazon API Gateway HTTP API must authorize requests using a JSON Web Token from a third-party OpenID Connect provider, with no custom code. Which solution meets these requirements?
Answer and explanation
Answer: C. HTTP APIs support a built-in JWT authorizer that validates signature, issuer, audience, and expiry against the provider's configuration, satisfying the no-code constraint. A Lambda authorizer is custom code. IAM authorization requires SigV4 signing rather than a third-party token. A usage plan controls throttling and quotas rather than identity.
62. An Amazon API Gateway REST API must be callable only by IAM principals using SigV4-signed requests. Which solution meets these requirements?
Answer and explanation
Answer: C. AWS_IAM authorization requires requests to be signed with SigV4 and evaluates the caller's IAM permissions. A Cognito authorizer validates user pool tokens rather than SigV4 signatures. API keys identify callers for usage plans and are not authentication. A Lambda authorizer handles custom token schemes.
63. An application must send an Amazon Cognito token to an API Gateway Cognito authorizer to prove the user's identity claims. Which token should the application send?
Answer and explanation
Answer: C. The ID token carries the user's identity claims and is what a Cognito user pool authorizer validates by default. The refresh token obtains new tokens and is never sent to an API. Credentials exchange is a separate identity pool flow. A client secret authenticates the application and must never be sent from a public client.
64. An organization must prevent a developer role from creating IAM roles that are more privileged than the developer. Which solution meets these requirements?
Answer and explanation
Answer: D. A permissions boundary caps the effective permissions of any role created, and conditioning role creation on attaching that boundary ensures developers cannot exceed their own ceiling. Granting iam:* is precisely the escalation path being prevented. A permissive service control policy removes the guardrail. A written standard is not an enforced control.
65. A bucket policy grants a cross-account role access to objects encrypted with a customer managed AWS KMS key, but the role still cannot read the objects. Which solution meets these requirements?
Answer and explanation
Answer: D. Objects encrypted with a customer managed key require the caller to hold decrypt permission on that key, granted in the key policy as well as the bucket policy. ListBucket affects listing rather than object retrieval. An endpoint policy applies only when traffic uses that endpoint. Service control policies cannot grant permissions; they only restrict.
66. An application must encrypt 50 MB files before storing them in Amazon S3 while minimizing calls to AWS KMS. Which solution meets these requirements?
Answer and explanation
Answer: A. Envelope encryption obtains a data key once, encrypts the payload locally, and stores the encrypted data key alongside the ciphertext, avoiding the KMS payload limit and reducing API calls. KMS Encrypt accepts at most four kilobytes. KMS key material cannot be exported. A static key in configuration is neither rotated nor protected.
67. A developer must grant a principal temporary, revocable permission to use one AWS KMS key for specific operations without editing the key policy. Which solution meets these requirements?
Answer and explanation
Answer: A. Grants provide programmatic, revocable permissions scoped to specific operations and are commonly created by AWS services on a caller's behalf. An alias is a friendly name. Rotation changes key material on a schedule. A replica extends a key to another Region.
68. Objects written to Amazon S3 must be encrypted so that reading them requires permission on a specific key, and every use of that key must appear in AWS CloudTrail. Which solution meets these requirements?
Answer and explanation
Answer: C. SSE-KMS with a customer managed key requires kms:Decrypt on that key and records each cryptographic operation in CloudTrail. S3 managed keys are applied transparently with no separate permission gate or key usage trail. A key in the deployment package is neither protected nor auditable. A bucket policy controls access without encrypting.
69. An application writes request payloads to logs, and those payloads sometimes contain payment card numbers. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: C, D. The reliable fix is not to write the data at all, and a data protection policy masks known sensitive patterns as a safety net for anything that slips through. Encryption protects logs from outside readers while the data is still recorded and visible to authorised staff. Shorter retention narrows the exposure window without removing it. Restricting readers is access control rather than data minimisation.
70. A Systems Manager Parameter Store SecureString parameter must be retrieved by an application. Which permissions does the application's role require?
Answer and explanation
Answer: B. A SecureString parameter is encrypted at rest with a KMS key, so retrieving it with decryption requires both the Systems Manager read permission and decrypt permission on that key. Neither permission alone is sufficient. PutParameter grants write access and does not permit reading the value.
71. Credentials must be kept out of a Git repository entirely. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: A, E. Keeping secrets out of source entirely and scanning commits before they land addresses both the practice and the accident. Committing ciphertext still places secret material in history and moves the key problem elsewhere. A .gitignore entry lists paths to ignore and does not remove anything already committed. Rotating a committed credential leaves every previous value in history.
72. An AWS Lambda function running in a VPC must retrieve a secret from AWS Secrets Manager without the traffic leaving the AWS network. Which solution meets these requirements?
Answer and explanation
Answer: D. Secrets Manager is reached through an interface endpoint powered by PrivateLink, which places an elastic network interface in the subnet so the call never traverses the internet. Gateway endpoints exist only for Amazon S3 and DynamoDB. A NAT gateway routes traffic to the internet, which the requirement excludes. Lambda functions in a VPC have no direct internet gateway path.
73. An Amazon RDS database credential must rotate every 30 days without any request failing during the rotation. Which solution meets these requirements?
Answer and explanation
Answer: A. The alternating users strategy keeps one credential valid while the other rotates, so in-flight connections are unaffected. The single user strategy changes the one credential in place, which can fail requests using the old value. A scheduled overwrite in Parameter Store has the same problem and no rotation framework. Manual switching implies downtime and human effort.
74. An Amazon S3 presigned URL must stop working after a short period even if it is shared with others. Which factor determines when the URL expires?
Answer and explanation
Answer: B. A presigned URL carries an explicit expiry, and if it was signed with temporary credentials it also stops working when those credentials expire, whichever comes first. Block Public Access governs public policies and ACLs rather than presigned URLs. Storage class affects retrieval cost and latency. Versioning preserves object history.
75. An AWS Lambda function receives a database password through an environment variable, and the plaintext value is visible to anyone who can describe the function. Which solution meets these requirements?
Answer and explanation
Answer: D. Lambda encryption helpers encrypt the variable with a KMS key so the console shows ciphertext and the function decrypts it at run time. Renaming the variable is obscurity rather than protection. Moving the value into the package embeds the secret in an artifact and requires a redeployment to change. Restricting the describe permission narrows who can read it without encrypting it.
76. An application must write diagnostic records that include a customer record but must not persist the customer's national identity number. Which solution meets these requirements?
Answer and explanation
Answer: C. Removing the value before it is written is the only approach that prevents persistence, which is what the requirement states. Restricting reads leaves the data stored and visible to authorised principals. A short retention period narrows the exposure window without removing it. Encrypting a different destination still persists the value.
77. Several applications need the same third-party API key, and the key must be stored once with a documented rotation schedule. Which solution meets these requirements?
Answer and explanation
Answer: B. Secrets Manager stores the value once, supports a rotation schedule with a rotation function, and serves it to each application through IAM. A String parameter is neither encrypted nor rotated. An encrypted S3 object protects the value at rest but has no rotation mechanism. Copying the key into each application's configuration defeats storing it once.
78. An application must authenticate end users and receive tokens that an Amazon API Gateway authorizer can validate. Which solution meets these requirements?
Answer and explanation
Answer: B. A Cognito user pool authenticates end users and issues tokens API Gateway validates. IAM users are for AWS access. A shared key does not identify individual users. Root credentials must never be used.
79. An application running on Amazon ECS with Fargate must call AWS services with least privilege. Which configuration is appropriate?
Answer and explanation
Answer: B. A task role supplies credentials to the application scoped to its needs. The task execution role is for pulling images and writing logs rather than application permissions. Keys in an image are extractable. Fargate tasks do not use an instance role.
80. A developer must allow a mobile application's users to access only their own objects in an S3 bucket. Which approach is appropriate?
Answer and explanation
Answer: B. A policy variable scoped to the identity restricts each user to their own prefix. Bucket-wide access exposes everyone's objects. An IAM user per mobile user does not scale. Presigning every object is impractical.
81. An API Gateway REST API must authorize requests using custom logic based on a bearer token. Which solution meets these requirements?
Answer and explanation
Answer: A. A Lambda authorizer runs custom validation logic and returns a policy. A Cognito authorizer validates Cognito tokens specifically. A resource policy restricts by principal and source. API keys identify callers for throttling rather than authorizing.
82. An application must encrypt a 20 MB payload with AWS KMS. Which approach is required?
Answer and explanation
Answer: B. KMS Encrypt has a small payload limit, so larger data is encrypted locally with a data key. KMS does not store payloads. A key policy governs access rather than performing encryption.
83. A developer must ensure objects uploaded to a bucket are encrypted with a specific KMS key. Which approach enforces this?
Answer and explanation
Answer: B. A bucket policy condition rejects a non-conforming upload. Default encryption applies the key when none is specified but does not reject a different one. Instructions are advisory. Block Public Access prevents public exposure.
84. An application must decrypt data encrypted with a KMS key in another account. Which permission is required in addition to the application's IAM policy?
Answer and explanation
Answer: B. Cross-account KMS use requires both an IAM grant and permission in the key policy. Keys are not copied between accounts. Re-encryption is unnecessary. Plaintext key material is never exposed.
85. An application must verify that an object downloaded from Amazon S3 was not altered in transit. Which approach is appropriate?
Answer and explanation
Answer: A. Checksum comparison detects alteration. Size and timestamp do not detect content changes of the same length. Re-downloading compares two potentially identical corruptions.
86. An application must encrypt data before it leaves the client so AWS never holds the plaintext. Which approach is appropriate?
Answer and explanation
Answer: C. Client-side encryption means AWS receives only ciphertext. Server-side encryption and default encryption both encrypt after receipt. TLS protects transit while the service still sees plaintext.
87. An application must rotate the key used for client-side encryption without re-encrypting existing data. Which approach is appropriate?
Answer and explanation
Answer: A. Envelope encryption isolates rotation to the wrapping key. Re-encrypting everything is expensive. A single key for all objects forces full re-encryption. Deleting and recreating loses the original data.
88. An application must authenticate to an external API using a credential that must not appear in its code or configuration. Which approach is appropriate?
Answer and explanation
Answer: B. Run-time retrieval leaves no credential in code or configuration and picks up rotation. Environment variables, packaged files, and repositories all place the value with the application.
89. An application must call an AWS service in another account with permissions scoped to a single operation. Which approach is appropriate?
Answer and explanation
Answer: D. A narrowly scoped assumed role limits the cross-account access precisely. A broad resource policy over-grants, stored keys are long-lived, and root credentials must never be used.
90. An API must reject requests whose payload does not match an expected schema before invoking the backend. Which configuration is appropriate?
Answer and explanation
Answer: A. Request validation rejects malformed payloads at the API before invoking the backend. Backend validation pays for the invocation. A WAF rule inspects for threats rather than schema conformance. Throttling limits rate.