AWS Developer Associate Practice Questions and Explanations
The best practice questions for AWS Developer Associate test application decisions and explain why each distractor fails.
- These original examples cover least-privilege access, duplicate event handling, release safety, and evidence-based troubleshooting.
- They illustrate current-guide concepts but are not official AWS items or predictions of the live exam.
On this page10 sections
- Question 1: narrow permissions for a function
- Question 2: repeated queue message
- Question 3: secret rotation
- Question 4: failed release after package change
- Question 5: gradual rollout
- Question 6: troubleshoot a permission failure
- Question 7: high latency after a dependency call
- Question 8: values differ by environment
- Question 9: interpreting a weak practice result
- How to study the explanations
These questions are newly written study examples based on the current AWS Developer Associate outline. They are not copied from AWS's live exam, and they do not predict exact exam content. For each one, identify the requirement before selecting a service or configuration. The explanations focus on why the correct choice fits and why tempting alternatives fail.
Question 1: narrow permissions for a function
A Lambda function must upload generated reports to one S3 bucket. The function currently receives AccessDenied. The developer wants the smallest safe permission change. What should they do?
- A. Attach AdministratorAccess to the execution role.
- B. Add the required object-write action to the function's execution role, scoped to the report objects in the named bucket, and verify any bucket or encryption-key policy.
- C. Store a developer IAM user's access key in an environment variable.
- D. Make the bucket public so the function can write.
Answer: B. The function's execution role is the workload identity. Add only the necessary action and resource scope, then evaluate resource-policy and key-policy conditions if denial persists. A grants far more access than needed; C introduces a long-lived personal credential and does not repair the runtime identity; D creates exposure and does not provide a sound authorization design.
Question 2: repeated queue message
A queue-triggered worker calls an external billing service. If the worker times out after the billing request succeeds but before its acknowledgement completes, the same message may be processed again. Which design best prevents a duplicate charge?
- A. Assume the queue delivers each message exactly once.
- B. Use a stable business request identifier and persist completion so repeated delivery returns the prior outcome without repeating the charge.
- C. Increase the worker timeout to several hours.
- D. Disable retries for every failure.
Answer: B. A timeout can leave the caller uncertain about whether a side effect occurred, and delivery retry does not guarantee that the business action happened only once. An idempotency key or durable deduplication record makes repeated attempts safe. A assumes away a normal distributed-systems condition; C may reduce some timeouts but cannot prevent redelivery; D can discard transiently failed work.
Question 3: secret rotation
An application connects to a database using a password that is committed in a source repository. The organization rotates the database credential regularly and wants to avoid rebuilding the application for every rotation. Which approach best fits?
- A. Keep the password in source but encrypt the repository.
- B. Retrieve the current secret at runtime from a managed secret store using the application's role, and design refresh and failure handling for rotation.
- C. Put the new password in a public parameter so every environment can read it.
- D. Use a developer's personal password and change it before each deployment.
Answer: B. The secret should not live in source code, and the workload should access it through its own permissioned identity. Runtime retrieval permits rotation without embedding the value in each build, though the application still needs appropriate caching, refresh, and outage behavior. Encrypting a repository does not remove the credential from code history; C exposes it; D couples production access to a human account.
Question 4: failed release after package change
A new version deploys but immediately fails with a missing-module error. The same code works on a developer laptop. What is the best first investigation?
- A. Give the function broader IAM permissions.
- B. Inspect the deployment artifact and runtime dependency packaging, then compare the deployed environment with the supported runtime.
- C. Increase the database connection pool.
- D. Disable logging to reduce overhead.
Answer: B. A missing-module error points first to packaging, dependency inclusion, or runtime compatibility. Compare the artifact built for deployment with the local environment and verify the function's runtime. IAM may matter for an AccessDenied error but does not normally install a missing library. Database capacity and logging are unrelated to the reported failure.
Question 5: gradual rollout
A team wants to expose a new application version to a small portion of traffic first, watch error and latency metrics, and stop the rollout if the new version is unhealthy. Which release approach is most aligned?
- A. Replace every running instance at once and inspect only after completion.
- B. Use a controlled traffic-shift deployment with health evaluation and a rollback path.
- C. Upload the new artifact to a different folder but leave routing unchanged.
- D. Remove monitoring to avoid false alarms.
Answer: B. A controlled shift limits the initial blast radius and allows the team to observe health before increasing exposure. The deployment configuration must define what metrics or alarms indicate failure and how traffic returns to the stable version. A makes the whole fleet vulnerable at once; C does not describe a release; D removes evidence needed to judge the rollout.
Question 6: troubleshoot a permission failure
A deployed service returns AccessDenied when reading an encrypted object. The role has an S3 read action for the object, but the object uses a customer-managed KMS key. What should the developer verify?
- A. Whether the role is authorized to decrypt with that key and the key policy permits the use, in addition to the S3 access.
- B. Whether the object is made publicly readable.
- C. Whether the function timeout is longer than one minute.
- D. Whether the deployment package contains an additional SDK copy.
Answer: A. Access involves the object service permission and the encryption key authorization. The role may need the relevant decrypt action, and the key policy must permit its use. Public access is not an appropriate fix for an encrypted private object. Timeout and packaging are not the first explanation for an authorization denial.
Question 7: high latency after a dependency call
An API's latency rises only when it calls a third-party endpoint. CPU and memory remain normal, and logs show the external request taking most of the duration. Which next step is best?
- A. Increase function memory without further investigation.
- B. Use the timing evidence to investigate the dependency path, set appropriate timeouts and retry behavior, and consider caching only if data freshness permits.
- C. Grant the function administrator permissions.
- D. Disable request metrics.
Answer: B. The logs identify the external call as the dominant latency source. A reasonable response is to examine dependency reliability, configure bounded timeouts and retries, and assess whether a cache can meet freshness requirements. Increasing memory may not improve network wait; administrator access is unrelated; removing metrics eliminates useful evidence.
Question 8: values differ by environment
A release works in test but sends production requests to the test API endpoint. The code package is identical across environments. What design change best prevents this class of mistake?
- A. Hard-code the test endpoint in the source for consistency.
- B. Keep environment-specific configuration outside the application artifact, apply the correct value through the deployment configuration, and validate it before promotion.
- C. Ask each developer to edit the source before deployment.
- D. Increase the number of retries.
Answer: B. Separate configuration from the immutable code artifact and control it in the release process. Validate the destination before production traffic is enabled. A and C make environment selection error-prone; D can repeat the wrong request more often.
Question 9: interpreting a weak practice result
A candidate earns 68% on a third-party quiz and sees several missed IAM and deployment questions. What is the most defensible next step?
- A. Convert 68% into an AWS scaled score and book immediately.
- B. Review the explanations, identify the exact policy and release concepts missed, and solve fresh scenarios after targeted study.
- C. Ignore the weak domains because the practice score is over half.
- D. Memorize the answer letters and repeat the same quiz until perfect.
Answer: B. A third-party percentage is not an AWS scaled score conversion. Use item-level explanations to identify a skill gap, then test transfer with new questions. AWS publishes 720 on a 100-to-1,000 scaled scale but not a raw cutoff. C leaves known weaknesses untreated; D measures memory of the quiz rather than competence.
How to study the explanations
After each question, cover the answer and explain the decision aloud or in writing. Name the constraint that determines the choice, then state why every other option fails. If you cannot explain a result, look up the specific behavior in the official AWS guide or service documentation. Avoid collecting screenshots of answer keys without recording what you learned.
For a timed set, spend roughly two minutes per presented item on average because the exam allows 130 minutes for 65 questions. A hard question can consume more, so flag it when your reasoning stops improving and continue. In review, correct only when you can identify an overlooked requirement or factual misunderstanding, not because a different option feels more elaborate.
Use original questions to learn, not to imitate secured live content. AWS does not publish the identity of unscored pretest items, so treat every exam question seriously. Practice sets can improve reasoning, but they cannot guarantee a particular score or reveal the live exam form.
Common questions
Are these official exam questions?
No. They are original examples and do not reproduce protected live items.
How should I use a practice set?
Explain the requirement, correct answer, and each distractor; then retest the concept using new scenarios.
Do quiz percentages predict the AWS score?
No. A third-party percentage is not an AWS scaled-score conversion.