63 practice questions for Domain 3 of the AWS Certified Developer - Associate (DVA-C02) exam, which makes up 24% of its scored content. Your answers count towards one score and one timer for the whole exam.
Domain 3: Deployment
91. A developer must invoke an AWS Lambda function locally with a simulated Amazon API Gateway event before deploying it. Which AWS SAM CLI command meets these requirements?
Answer and explanation
Answer: C. sam local start-api runs a local HTTP endpoint that invokes the function with an API Gateway style event, which is the local test loop described. sam deploy pushes the stack to AWS. sam package uploads artifacts. sam validate checks template syntax without executing anything.
92. An AWS CodePipeline deployment must not proceed to production until a named reviewer approves it. Which solution meets these requirements?
Answer and explanation
Answer: C. A manual approval action halts the pipeline until an authorised principal approves or rejects, and an SNS topic notifies the reviewer. A fixed pause resumes regardless of approval. An alarm reacts to metrics rather than gating on human judgement. Artifact replication concerns availability of build outputs.
93. A container image must be scanned on every push, and the pipeline must fail if any critical vulnerability is found. Which solution meets these requirements?
Answer and explanation
Answer: B. ECR enhanced scanning reports findings that a gating action can evaluate and fail the pipeline on before promotion. Manual review does not scale and is easily skipped. Listing packages produces an inventory without vulnerability data. Restricting push permissions is access control rather than vulnerability management.
94. Several AWS Lambda functions share the same libraries, and a dependency update must not require repackaging each function. Which solution meets these requirements?
Answer and explanation
Answer: A. A layer packages libraries once and is attached to multiple functions, so a dependency update means publishing a new layer version rather than rebuilding every function. A container image per function duplicates the dependency in each. Downloading from S3 adds latency on every cold start. EFS can hold large dependencies but introduces VPC configuration and mount overhead for a problem layers already solve.
95. An AWS CodeBuild project must produce an artifact that AWS CodePipeline passes to a later deployment stage. Which solution meets these requirements?
Answer and explanation
Answer: C. The buildspec artifacts section declares which files form the output artifact, and CodePipeline stores and passes it between stages. The appspec describes how CodeDeploy installs an application. Template parameters supply values to CloudFormation. A repository policy governs image access.
96. A developer must define AWS infrastructure in TypeScript and have it synthesized into an AWS CloudFormation template. Which solution meets these requirements?
Answer and explanation
Answer: A. The CDK lets infrastructure be expressed in general-purpose languages and synthesizes CloudFormation templates. SAM uses a declarative YAML shorthand for serverless resources. CodeBuild compiles and tests code. Systems Manager Automation runs operational runbooks.
97. The same AWS Lambda deployment package must behave differently in test and production without being rebuilt. Which solution meets these requirements?
Answer and explanation
Answer: D. Externalising configuration means one tested artifact is promoted unchanged, which is what guarantees production runs what was tested. Hardcoding requires a code change per environment. Building separate packages means production runs an artifact that was never tested. Runtime choice is unrelated to environment configuration.
98. An artifact that passed testing in staging must be the exact artifact deployed to production. Which solution meets these requirements?
Answer and explanation
Answer: C. Dependency resolution, build tooling versions, and timestamps can all differ between runs, so a rebuild is not guaranteed to reproduce the tested artifact. Rebuilding from the same commit or Dockerfile has the same problem. Comparing checksums after deployment detects a difference only once production is already running the new artifact.
99. A team must shift traffic to a new AWS Lambda version gradually and revert automatically if the error rate rises. Which solution meets these requirements?
Answer and explanation
Answer: B. An alias splits invocations between two versions by weight, and CodeDeploy automates the shift while monitoring an alarm to roll back automatically. Changing function names pushes deployment concerns into every caller. Updating $LATEST replaces the code for everyone at once with no gradual shift. A second function with a stage change is an abrupt cutover without automated rollback.
100. The same AWS CloudFormation stack must be deployed into twelve accounts across three Regions, and accounts added later must receive it automatically. Which solution meets these requirements?
Answer and explanation
Answer: B. StackSets deploy one template across many accounts and Regions, and targeting an organizational unit with automatic deployment covers accounts added later without further action. Manual creation is inconsistent and misses new accounts. Nested stacks operate within one account. A stage per account is duplicated configuration to maintain.
101. An Amazon API Gateway REST API must expose development and production endpoints that invoke different Lambda aliases and enforce different throttling limits. Which solution meets these requirements?
Answer and explanation
Answer: A. Stages represent deployments of the same API with their own stage variables, which can select a Lambda alias, and their own throttling and caching settings. Duplicating the API doubles maintenance for every resource change. A query string switch puts environment selection in the hands of callers and offers no throttling separation. Separate accounts are heavier than the requirement needs.
102. A developer must understand the relationship between an AWS Lambda version and an alias. Which statement is correct?
Answer and explanation
Answer: C. Publishing creates an immutable version, and an alias is a named pointer that can be repointed and can weight traffic between two versions. The mutability is not reversed, the constructs are distinct, and aliases point to versions rather than the other way round.
103. A pipeline must run unit tests, deploy to a test environment, run integration tests against it, and then deploy to production. Which solution meets these requirements?
Answer and explanation
Answer: D. Integration tests require a deployed environment, so they belong after the test deployment and before production promotion. Running them before any deployment is impossible without an environment. Testing after production deployment means defects reach users. Local pre-commit testing is neither consistent nor gating.
104. An AWS CodeDeploy blue/green deployment to Amazon ECS must let the team exercise the replacement task set before production traffic is shifted. Which solution meets these requirements?
Answer and explanation
Answer: A. CodeDeploy for ECS supports a separate test listener so the replacement task set can be exercised before any production traffic is shifted, gated by a validation hook. A pipeline approval pauses without providing a test endpoint. A canary shifts real traffic immediately. An AfterAllowTraffic hook runs once production traffic is already flowing.
105. A build must not proceed if a template would create an Amazon S3 bucket with public access. Which solution meets these requirements?
Answer and explanation
Answer: C. Scanning templates in the pipeline evaluates the intended configuration before any resource exists and fails the build, which is genuine prevention. A Config rule detects the bucket after creation. A manual approval depends on a reviewer noticing the setting in a large template. A CloudTrail alarm is retrospective.
106. An AWS CloudFormation template must receive a database password at deployment without the value appearing in the template or the console. Which solution meets these requirements?
Answer and explanation
Answer: C. NoEcho masks a parameter value in console and API output, and a dynamic reference retrieves the secret at deployment so it never enters the template. A default value places the password in the template file. Mappings are static template content and equally exposed. Exporting a password publishes it to any stack that can import it.
107. An AWS SAM template defines eight functions that share the same runtime, timeout, and environment variables. Which solution expresses this most concisely?
Answer and explanation
Answer: A. The SAM Globals section applies shared properties across resource types, removing repetition. Repeating properties invites drift. Nested stacks add structure without addressing repeated properties. Mappings hold static lookup values rather than default resource properties.
108. An AWS CloudFormation template has grown large, and several sections are reused across projects. Which solution meets these requirements?
Answer and explanation
Answer: A. Nested stacks encapsulate reusable components that a parent stack instantiates, keeping each template manageable and the components consistent. Duplication guarantees drift. The Metadata section carries information for tools rather than resources. Hardcoding values reduces reusability.
109. An AWS CloudFormation template must read a value from AWS Secrets Manager at deployment without the value appearing in the template or its parameters. Which solution meets these requirements?
Answer and explanation
Answer: C. Dynamic references resolve the secret at deployment so the value is never written into the template or its parameters. A default value places the secret in the template file. Exporting a secret publishes it to importing stacks. Mappings are static template content.
110. A pipeline must run integration tests against an Amazon API Gateway API that has been deployed to a test stage, using the same test suite for every environment. Which solution meets these requirements?
Answer and explanation
Answer: C. Passing the stage invoke URL into the test suite lets one suite target whichever environment the pipeline just deployed. Testing against production after deployment means defects reach users. A mock integration on production returns canned responses rather than exercising the backend. Local runs are neither consistent nor gating.
111. An automated test must invoke an AWS Lambda function with a representative Amazon S3 event during the pipeline's test stage. Which solution meets these requirements?
Answer and explanation
Answer: A. A stored JSON test event matching the source schema exercises the function's real code path deterministically inside the pipeline. Uploading to the production bucket performs a real side effect. An empty payload does not exercise the handler's parsing logic. Waiting for a production event is neither deterministic nor timely.
112. An AWS Elastic Beanstalk environment must be updated with no reduction in capacity and no downtime, and the team accepts paying for extra instances during the deployment. Which deployment policy meets these requirements?
Answer and explanation
Answer: D. Rolling with additional batch launches extra instances before replacing existing ones, so full capacity is maintained at the cost of temporary extra instances. A plain rolling deployment reduces capacity while each batch is replaced. All at once takes the environment down briefly. Immutable deployments preserve capacity but create a separate temporary Auto Scaling group rather than sharing one.
113. An AWS CodeDeploy blue/green deployment to Amazon EC2 must stop and roll back if any instance fails application validation. Which solution meets these requirements?
Answer and explanation
Answer: D. ValidateService runs after the application starts and a non-zero exit marks the instance deployment failed, and rollback on failure reverts the deployment group automatically. BeforeInstall runs too early to validate a running service. AllAtOnce with no hooks provides no validation signal. Operator-triggered rollback is not automatic.
114. An AWS Elastic Beanstalk deployment must be reversible by discarding the new instances, without touching the instances currently serving traffic. Which deployment policy meets these requirements?
Answer and explanation
Answer: A. Immutable deployments launch a parallel Auto Scaling group and swap instances in only after they pass health checks, so rollback is terminating the new group. Rolling and rolling with additional batch both replace instances within the existing group. All at once updates every instance simultaneously.
115. An Amazon ECS service must be updated to a new task definition while never dropping below its current healthy task count. Which solution meets these requirements?
Answer and explanation
Answer: D. A minimum healthy percent of 100 prevents dropping below current capacity, and a maximum above 100 allows extra tasks to start before old ones stop. A minimum of 0 permits capacity to fall to zero during the update. Permanently raising the desired count changes capacity rather than deployment behaviour. The circuit breaker governs automatic rollback.
116. An Amazon API Gateway stage must pass an environment-specific value to the AWS Lambda function it invokes, without changing the function code between environments. Which solution meets these requirements?
Answer and explanation
Answer: D. Stage variables let one API definition target different Lambda aliases per stage, which keeps the function code and the API definition identical across environments. Updating function environment variables per deployment reintroduces a per-environment change. A function per environment duplicates the artifact. Branching on a request path puts environment logic into the application.
117. A team must trigger build, test, and deployment actions automatically whenever code is merged into the main branch. Which solution meets these requirements?
Answer and explanation
Answer: B. A source action watching the main branch starts an execution on each merge, which is the continuous integration behaviour required. A scheduled run delays feedback and may batch unrelated changes. Manual starts depend on people remembering. Watching every branch triggers executions for work that is not ready to deploy.
118. A release must be identifiable so that a specific deployed version can be traced back to the exact commit that produced it. Which solution meets these requirements?
Answer and explanation
Answer: C. A version tag carried from commit to artifact to deployed resource makes the chain traceable in both directions. A timestamp identifies when rather than what. An execution identifier alone does not resolve to a commit without additional lookup. Recording the initiator identifies who rather than which code.
119. An existing AWS SAM template must be updated to add a new function without redeploying unrelated resources in the stack. Which solution meets these requirements?
Answer and explanation
Answer: B. CloudFormation computes the difference and acts only on resources that change, and a change set shows that difference before it is applied. Deleting and recreating the stack causes an outage and can lose data. A separate stack duplicating shared resources creates drift. Direct console edits cause stack drift and are lost on the next update.
120. A deployment strategy must expose a new version to a small percentage of production traffic for a fixed period before completing the shift. Which deployment configuration meets these requirements?
Answer and explanation
Answer: A. A canary shifts a fixed percentage, holds for the interval, then completes, which is exactly the described behaviour. Linear shifts repeatedly in equal increments rather than one hold-then-complete step. All-at-once exposes every request immediately. Blue/green describes the environment topology rather than a percentage-and-hold schedule.
121. A developer must define a serverless application's Lambda functions, API, and table in a template with shorthand syntax. Which solution meets these requirements?
Answer and explanation
Answer: B. SAM provides shorthand for serverless resources and deploys them as one stack. Console creation is not repeatable. A CLI script has no state tracking or rollback. An exported template may not reproduce the environment reliably.
122. A container image must be stored so Amazon ECS can pull it during deployment. Which solution meets these requirements?
Answer and explanation
Answer: A. ECR is the container registry ECS pulls from. S3 stores objects rather than serving as a registry. CodeArtifact hosts language packages. EBS snapshots are block storage.
123. A build must produce an artifact whose dependencies are resolved from a private repository and a public one. Which solution meets these requirements?
Answer and explanation
Answer: C. CodeArtifact with an upstream connection proxies the public repository so one endpoint serves both, with caching and control. Separate downloads require two configurations. Vendoring bloats the repository. Manual bundling is error-prone.
124. A developer must test a Lambda function locally before deploying it. Which solution meets these requirements?
Answer and explanation
Answer: D. The SAM CLI invokes functions locally with sample events for rapid iteration. Deploying to test is slower. Skipping integration testing leaves the invocation path unverified. Production testing exposes users.
125. An integration test must run against AWS services without affecting other developers' resources. Which approach is appropriate?
Answer and explanation
Answer: A. Isolated ephemeral stacks remove contention and guarantee a known starting state. A shared environment creates interference. Production testing risks live data. Unit tests do not exercise service integration.
126. A developer must mock AWS service responses in unit tests without calling the services. Which approach is appropriate?
Answer and explanation
Answer: A. Injecting a mocked client keeps unit tests fast and deterministic. Real calls make tests slow and flaky. Deployment observation is not unit testing. Skipping leaves the logic untested.
127. A Lambda function must be updated so that a percentage of invocations use the new version while the rest use the previous one. Which solution meets these requirements?
Answer and explanation
Answer: B. Alias weighted routing splits invocations between two published versions. In-place updates shift everything at once. A second function with application routing duplicates the deployment mechanism. Environment variables do not version code.
128. A deployment to Amazon ECS must shift traffic to a new task set and roll back automatically if errors rise. Which solution meets these requirements?
Answer and explanation
Answer: D. Blue/green with alarm-based rollback shifts traffic and reverts automatically. An in-place update replaces tasks without a rollback trigger. Stopping and scaling to zero both cause outages.
129. An application's configuration must change without redeploying the code, with a gradual rollout. Which solution meets these requirements?
Answer and explanation
Answer: D. AppConfig delivers configuration with gradual rollout and automatic rollback. Environment variables and packaged files require redeployment. Hardcoding requires a code change.
130. A CloudFormation stack update must replace a resource, and the developer must know this before applying it. Which indication does a change set provide?
Answer and explanation
Answer: D. A change set distinguishes Add, Modify, and Replace actions per resource, so a replacement is visible before execution. It does not report a bare count, a cost estimate, or a duration estimate.
131. A serverless application's deployment package exceeds the size limit for inline editing. Which approach is appropriate?
Answer and explanation
Answer: B. Referencing a package in S3 supports larger deployment artifacts. Removing dependencies may break the function, splitting changes the architecture for a packaging limit, and memory does not affect package size.
132. A developer must reproduce a defect that occurs only with production-like data volumes. Which approach is appropriate?
Answer and explanation
Answer: D. Anonymized production-scale data in a test environment reproduces the conditions safely. Production testing risks users, small samples do not exhibit scale-dependent defects, and a larger instance does not supply data.
133. An integration test must verify behaviour against a service the team does not control and which rate limits requests. Which approach is appropriate?
Answer and explanation
Answer: D. Recorded responses give fast deterministic tests, with a scheduled live suite catching contract drift. Calling live in every run exhausts the limit, skipping loses coverage, and a higher limit does not make tests deterministic.
134. A deployment must be rolled back automatically if the application's error rate rises after traffic shifts. Which configuration is appropriate?
Answer and explanation
Answer: A. An alarm associated with the deployment group triggers automatic rollback. Manual monitoring depends on a person, a quiet period limits exposure without reverting, and a longer wait delays completion.
135. A Lambda alias must be updated to a new version while keeping the previous version available for immediate rollback. Which approach is appropriate?
Answer and explanation
Answer: A. Publishing versions and repointing the alias makes rollback immediate. Overwriting without publishing leaves nothing to revert to, deleting removes the rollback target, and a second function duplicates the deployment path.
136. An application's configuration change must be rolled out gradually with automatic reversion on error. Which approach is appropriate?
Answer and explanation
Answer: C. AppConfig rolls configuration out gradually and reverts when the monitored alarm fires. Simultaneous updates expose everything, manual monitoring depends on a person, and redeployment couples configuration to code.
137. A CloudFormation stack update must be prevented from replacing a database resource. Which approach is appropriate?
Answer and explanation
Answer: A. A stack policy denying replacement blocks the update action on that resource. DeletionPolicy governs stack deletion, termination protection prevents stack deletion, and removing the resource from the template deletes it.
138. A deployment must verify the application is serving correctly before the previous environment is removed. Which approach is appropriate?
Answer and explanation
Answer: B. A validation hook gates termination on a verified outcome. Immediate termination removes the rollback path, a fixed wait assumes success, and terminating first leaves no way back.
139. A CloudFormation template must reference a value stored in Systems Manager Parameter Store at deployment time. Which approach is appropriate?
Answer and explanation
Answer: A. A Systems Manager parameter type resolves the value at deployment. Hardcoding requires a template change, passing manually is error-prone, and a custom resource adds complexity for a built-in capability.
140. A CloudFormation stack must expose a value for another stack to consume. Which construct is required?
Answer and explanation
Answer: A. An exported Output can be imported cross-stack. An unexported Output is visible only on the stack itself. Parameters are inputs and Mappings are lookup tables.
141. A SAM template must define a Lambda function triggered by an API endpoint. Which construct is appropriate?
Answer and explanation
Answer: C. A SAM Api event source creates the API and wires the integration. Manual API resources are the verbosity SAM removes. Events rules and S3 notifications are different trigger types.
142. A CDK stack must be deployed to an account and Region for the first time. Which step is required?
Answer and explanation
Answer: D. Bootstrapping provisions the resources the CDK needs for deployment. Stack limits are rarely the constraint, the bootstrap creates the asset bucket, and CloudFormation requires no enablement.
143. A CloudFormation deployment must create resources in a specific order where the dependency is not implied by a reference. Which attribute is appropriate?
Answer and explanation
Answer: C. DependsOn declares an explicit ordering dependency. Condition gates creation, Metadata attaches information, and DeletionPolicy governs deletion.
144. A CloudFormation template must produce different resource properties per environment without maintaining separate templates. Which construct is appropriate?
Answer and explanation
Answer: D. A Mapping supplies per-environment values from one template. Separate templates drift, hardcoded values require edits, and Outputs export rather than select values.
145. An application's infrastructure code must be tested before deployment. Which approach is appropriate?
Answer and explanation
Answer: C. Assertions against the synthesized template verify intent before deployment. Deploying to inspect is slow, review depends on a reviewer, and syntax validation does not check the resulting resources.
146. A SAM application must be tested locally with an API endpoint before deployment. Which command is appropriate?
Answer and explanation
Answer: D. A local API exercises the endpoint and integration locally. Deploying is slower, direct invocation skips the API layer, and unit tests do not cover the integration.
147. A CloudFormation stack must be updated without CloudFormation attempting to change a resource modified outside the stack. Which approach is appropriate?
Answer and explanation
Answer: C. Detecting drift and reconciling the template prevents an unexpected revert. Accepting the revert undoes the external change, removing the resource deletes it, and recreating the stack is disruptive.
148. An infrastructure template must reference a secret without the value appearing in the template or the stack's events. Which approach is appropriate?
Answer and explanation
Answer: B. A dynamic reference resolves the secret without placing it in the template. Parameters appear in stack details, hardcoding places it in source control, and Outputs expose it.
149. A CDK application must reuse a pattern across several stacks with typed configuration. Which construct is appropriate?
Answer and explanation
Answer: C. A custom construct encapsulates the pattern with typed properties. Copies drift, generation loses type safety, and Mappings supply values rather than encapsulate patterns.
150. A CloudFormation stack must wait for an application on an instance to report readiness before completing. Which construct is appropriate?
Answer and explanation
Answer: A. A CreationPolicy waits for signals from the instance. DependsOn orders creation without waiting for readiness, a wait condition requires a handle to signal, and Outputs export values.
151. A template must create a resource only when a parameter has a specific value. Which construct is appropriate?
Answer and explanation
Answer: C. A Condition gates resource creation. Mappings look up values, DependsOn orders creation between resources, and Metadata attaches information.
152. An application's infrastructure must be deployed through a pipeline rather than from a developer workstation. Which benefit does this provide?
Answer and explanation
Answer: C. Pipeline deployment gives reproducibility, review, and an audit trail. Speed, permissions, and template size are not the benefit.
153. A SAM template must grant a function permission to read from a DynamoDB table with minimal policy authoring. Which approach is appropriate?
Answer and explanation
Answer: C. SAM policy templates provide scoped permissions with minimal authoring. Wildcard actions, managed full access, and administrator permissions all over-grant.