Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

AWS Developer Associate Master Guide 2026

Updated 13 min read
Key takeaway

AWS Certified Developer - Associate tests developing, testing, deploying, and debugging cloud applications with AWS.

  • The current exam has 65 questions in 130 minutes, including 50 scored and 15 unscored items; the passing score is 720/1,000 scaled.
  • AWS recommends one year of hands-on experience, but does not require it to register.
On this page17 sections
  1. What the certification measures
  2. Current exam facts
  3. A version transition is underway
  4. The four domains
  5. Development with AWS Services
  6. Security
  7. Deployment
  8. Troubleshooting and Optimization
  9. Worked example: a reliable order update
  10. What is outside the exam’s developer role
  11. How to prepare
  12. Exam and certification details
  13. How to reason through developer scenarios
  14. Use the domain weights without turning them into quotas
  15. A practical study sequence
  16. Test-day decisions and pacing
  17. Plan around the 2026 exam transition

What the certification measures

AWS Certified Developer - Associate focuses on the work of building and maintaining applications that use AWS services. The exam assesses development with AWS services, application security, deployment, troubleshooting, and optimization. It expects a developer to reason about code behavior and service integrations, rather than design an entire enterprise architecture or administer servers and network infrastructure.

AWS recommends at least one year of hands-on experience developing and maintaining applications with AWS services. This describes the target candidate, not an eligibility gate. Recommended general knowledge includes a high-level programming language, application lifecycle management, cloud-focused application development, functional application development, and development tools.

Current exam facts

DetailCurrent exam
Presented questions65
Scored questions50
Unscored questions15, not identified
Duration130 minutes
Response typesMultiple choice and multiple response
Passing score720 on a scaled 100-to-1,000 range
Published US priceUS$150

AWS says unanswered questions count as incorrect and there is no penalty for guessing. The exam includes 15 unscored items that are not identified. The current guide also says emerging technology questions may appear as pretest content and do not affect the score. Since you cannot identify unscored questions, answer every item carefully.

A version transition is underway

As of October 6, 2026, AWS lists the current Developer Associate exam as available through December 1, 2026. Registration for an updated version opens October 27, 2026. AWS has not yet published the updated version’s complete exam guide in the sources used for this article. Candidates testing before the last date should prepare for the current guide; candidates booking the updated version should use its guide and resources once AWS publishes them.

Do not assume the current four-domain outline and service references apply unchanged after the update. Check the exam name and version in your AWS Certification Account and match your study material to that version. The transition affects more than a code label: exam objectives and preparation resources can change.

The four domains

DomainWeightWhat you practise
Development with AWS Services32%Application code, service APIs, Lambda, data stores, messaging, and resilient integrations
Security26%Authentication, authorization, encryption, secrets, and sensitive data handling
Deployment24%Artifacts, testing, environments, CI/CD execution, deployment strategies, and rollback
Troubleshooting and Optimization18%Root cause analysis, logs and metrics, tracing, debugging, and performance improvements

Weights describe portions of scored content, not exact question counts. Development is the largest domain, but security and deployment together account for half of scored content. Preparation should connect them: a function may work correctly but expose secrets, a pipeline may deploy a build without adequate tests, or a performance fix may create duplicate message processing.

Development with AWS Services

This domain covers application code hosted on AWS, serverless code, and data stores used by applications. Tasks include using SDKs and APIs, handling events and messages, writing tests, developing Lambda functions, connecting private resources, configuring handlers and timeouts, and tuning function performance.

Understand application patterns such as synchronous calls, asynchronous messaging, event-driven processing, stateful and stateless components, and tight or loose coupling. For an order service, an API can validate a request and store an order, then publish an event for downstream fulfillment. The API response should not depend on every downstream task completing if the business can accept asynchronous processing.

Data store tasks include partition keys, consistency, query versus scan, indexes, serialization, caching, and lifecycle. A query that uses a known key or index differs from scanning a table to inspect every item. A high-cardinality partition key can distribute access more evenly than a small set of hot keys. Choose patterns from access needs, not only familiarity.

Security

Developers need to authenticate users and authorize application actions, obtain programmatic access to AWS, assume roles, and make authenticated service calls. Avoid long-lived credentials in source code. Use scoped roles and application-level authorization so that a user can access only the records permitted to them.

Encryption topics include data at rest and in transit, client-side and server-side encryption, key use and rotation, and cross-account access. Sensitive data work includes classifying data, protecting environment variables, using a secrets manager, sanitizing data, masking output, and preventing sensitive values from leaking through application logs.

A secure secret storage service does not help if code prints the secret to logs. Encryption does not replace authorization. A signed-in user may still be unauthorized to view another tenant’s record. Look at the full request path, from identity to data access and observability.

Deployment

Deployment work includes packaging dependencies and configuration, testing applications, automating integration tests, managing environments, infrastructure as code, and using existing CI/CD services and workflows. The candidate is expected to work within a pipeline, but the guide marks designing and creating CI/CD pipelines as out of scope. Focus on using pipeline stages and deployment strategies rather than designing the whole delivery system.

Understand version labels, branches, Lambda deployment packaging, API stages and custom domains, environment variables, test events, and rollback. A deployment should promote an artifact through development, test, and production without accidentally mixing configuration. A canary release exposes a change to a small portion of traffic first; if metrics fail, roll back using the existing strategy.

Troubleshooting and Optimization

Troubleshooting starts with symptoms and evidence. Read application and service logs, inspect metrics and traces, identify integration failures, and isolate whether a problem comes from code, permissions, configuration, or a dependency. Structured logs and correlation identifiers help connect a request across components, but logs should not contain sensitive values unnecessarily.

Optimization tasks include profiling code, adjusting concurrency and memory, managing message filters, caching, analyzing latency, and tuning resource use. A slow API could reflect cold starts, an inefficient database access pattern, network calls, retries, or queue backlog. Measure before changing settings so that the fix targets the bottleneck rather than shifting it elsewhere.

Worked example: a reliable order update

A mobile application calls an API to update a customer’s order. The API writes the order status to a data store, publishes an event for warehouse processing, and returns a response. Occasionally, the client retries after a timeout and creates duplicate warehouse actions. The logs currently include the full request body, including customer information.

First identify where duplicate effects arise. Make the operation idempotent using a stable request or order identifier, and ensure the consumer can detect a repeated event. Use an appropriate retry and error handling strategy rather than assuming a timeout means the write failed. Keep the API response and asynchronous processing contract clear to the client.

Then protect the application. Give the API runtime a scoped role for required resources, validate the user’s authorization for the specific order, and remove unnecessary personal data from logs. Add structured fields such as request identifiers and status codes without recording secrets or full customer payloads.

In deployment, run unit and integration tests for successful updates, duplicate events, and transient failures. Promote a tested artifact through configured environments. Use an existing deployment strategy that allows observation and rollback. Monitor error rate, latency, queue age, and duplicate suppression so the team can see whether the change works.

The scenario spans development, security, deployment, and troubleshooting. The best solution is not a new enterprise network architecture or a redesigned pipeline, both beyond the exam’s stated developer role. It is a set of application-level changes and operational checks tied to the failure.

What is outside the exam’s developer role

AWS’s guide says candidates are not expected to design distributed-system architectures, microservices architecture, database schemas, or data models; design and create CI/CD pipelines; administer IAM users and groups; administer servers or operating systems; or design AWS networking infrastructure. This boundary helps focus study on application development and use of AWS services.

That does not mean those topics never appear in application context. A developer still needs to understand how an application assumes a role, uses an API, handles a message, or accesses a private resource. The distinction is between using and securing application integrations and being responsible for designing the broader platform architecture.

How to prepare

Begin with the current guide’s task statements and in-scope service references. Pair conceptual study with small coding exercises using an SDK or CLI, a test event, a data store, and logging. Practise the patterns that the guide names: retries, error handling, idempotency, access, encryption, deployment environments, rollbacks, and root cause analysis.

AWS offers Skill Builder courses, Builder Labs, Cloud Quest, AWS Jam, official practice questions, and a practice exam. Use one core source, then add a lab or reference to clarify specific gaps. The exam is multiple-choice and multiple-response; a lab helps you understand service behavior but is not the exam format.

  1. Read one task statement and summarize what a developer must do.
  2. Implement or sketch the application pattern in a small example.
  3. Add a failure case such as duplicate delivery, denied access, or dependency timeout.
  4. Review logs, metrics, and traces that would help locate the issue.
  5. Answer fresh exam-style questions and explain why alternatives fail.
  6. Revisit weak topics using the correct guide for the version you plan to take.

Exam and certification details

The published US exam price is US$150. AWS offers Pearson VUE test centers and online proctoring. The exam is valid for three years once passed. To recertify, pass the current Developer Associate exam or earn AWS Certified DevOps Engineer - Professional, which automatically recertifies the Associate credential. AWS does not require a separate experience application after passing.

How to reason through developer scenarios

A reliable method is to separate the requirement from the implementation detail. First name the desired outcome, such as preventing duplicate charges, reducing deployment risk, limiting access, or locating the cause of a timeout. Then identify the application identity, AWS resource, and failure evidence involved. Eliminate any answer that violates an explicit condition, even when the service named in that option is otherwise familiar. This method is especially useful when two answers could work in general but only one meets a constraint such as least operational effort or least privilege.

For example, an AccessDenied message after a deploy is not an invitation to attach a broad policy. Verify the principal that made the call, the requested action and resource, and any resource or encryption-key policy. If an SDK call fails only in production, compare runtime configuration and role assignment with the working test environment. The error text, logs, and recent release change narrow the cause. Practice stating what evidence would distinguish these cases before choosing a fix.

Use the domain weights without turning them into quotas

The current domain weights provide a useful starting point for study time: Development with AWS Services is 32%, Security is 26%, Deployment is 24%, and Troubleshooting and Optimization is 18%. If you have 40 hours available, a naive proportional split would assign about 13, 10, 10, and 7 hours respectively. Treat that only as a first allocation. A learner with weak IAM reasoning may move several hours toward Security; a developer who has deployed one service for years may need to shift time toward unfamiliar services and troubleshooting.

The weights are not a guaranteed count of scored questions and do not reveal the raw number needed to pass. The 65 presented questions include 15 unscored items whose identity is not shown. The score is scaled from 100 to 1,000, with 720 passing, and AWS does not publish a raw-cutoff conversion. So use domain weights to decide what to study, then use feedback and fresh scenarios to test whether you can apply the knowledge.

A practical study sequence

A candidate new to AWS application work can organize preparation in phases. Start with the current guide and a diagnostic; do not begin by buying several overlapping courses. Next, study the largest domain and the security tasks that appear throughout application scenarios. Then review packaging, configuration, release behavior, and rollback. Finish the first pass with troubleshooting: logs, metrics, errors, timeouts, retries, performance and cost. Each phase should mix documentation, recall, and practice rather than consist entirely of passive video.

A candidate with six study hours each week might use two sessions for concepts, one for a small lab or code-reading exercise, and one for mixed questions with answer review. On weeks focused on identity, draw who assumes which role and which policy permits the action. On a deployment week, deliberately introduce a missing dependency or wrong environment variable in a test application and observe what logs reveal. Keep the lab small and delete resources to avoid unnecessary charges.

Test-day decisions and pacing

The current exam gives 130 minutes for 65 presented questions, or an average of two minutes each. Read the last sentence of a scenario to identify the decision requested, scan for constraints, and compare only options that satisfy them. If you have made a defensible choice but cannot gain more evidence by rereading, flag the item if available and move on. Multiple-response items need a final count check: select the number requested, not every option that sounds plausible.

Leave a short review window to check unanswered questions, multi-select counts, and marked items. Do not change an answer merely because another option sounds more advanced. Change it when you identify a missed constraint or factual mistake. AWS says unanswered questions count as incorrect and guessing has no penalty, so make a reasoned selection on every item before time expires. Complete provider identity and equipment checks before the exam clock begins.

Plan around the 2026 exam transition

AWS lists October 27, 2026 as the opening date to register for the updated Developer Associate exam and December 1, 2026 as the final test date for the current version. As of October 6, the accessible detailed guide describes the current version; the replacement guide is not yet available in the source pack. A candidate should record the version shown in the booking flow, keep notes aligned to that guide, and switch resources only when replacement objectives are published. Do not mix current domain weights with claims about a future blueprint.

A first attempt near the final current-version date leaves little room for the 14-calendar-day retake wait and appointment availability. If a retake is important, schedule the first attempt with a buffer or choose the updated version intentionally and prepare from its own guide. The transition is a planning fact, not a reason to rush through study or assume that passing training is equivalent to passing the exam.

Common questions

How many questions are on the current exam?

65 are presented: 50 scored and 15 unscored.

What is the passing score?

720 on a scaled 100-to-1,000 range.

Do I need one year of experience to register?

No. AWS recommends it for the target candidate but does not require it.

Does the exam test live coding?

The current guide describes multiple-choice and multiple-response items, not a live coding task.

When does registration for the updated version open?

AWS lists October 27, 2026, with December 1, 2026 as the last test date for the current version.