dc dotCreds
AWS Certified Developer - Associate Practice Test

AWS Developer Associate Practice Test

Start today’s free 10-question AWS Developer Associate set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 15, 2026, 12:15 AM CDT

Go Pro - One Time Unlock

Unlock the full DVA-C02 bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 AWS Developer Associate questions

Use this AWS Developer Associate practice test to review AWS Certified Developer - Associate DVA-C02. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Protect application dependencies 2. Security (26%)

You’ve identified that an S3 bucket is publicly accessible, containing sensitive PII data. Which service would be the most effective tool for proactively discovering and protecting this data within Amazon S3?

Concept tested:
Question 2 of 10
Objective Encrypt data 2. Security (26%)

Your organization requires automated rotation of encryption keys used to protect data at rest in Amazon S3. Which approach best aligns with this requirement and minimizes operational overhead?

Concept tested:
Question 3 of 10
Objective Develop code for AWS Lambda 1. Development with AWS Services (32%)

Your team is developing a REST API secured by an AWS Lambda authorizer. To control access to the API, you need to implement a mechanism that allows you to define custom authorization logic. What is the recommended approach?

Concept tested:
Question 4 of 10
Objective Use logs metrics and traces 4. Troubleshooting and Optimization (18%)

You’ve deployed a microservice that generates extensive logs. You want to analyze these logs to identify patterns and troubleshoot issues efficiently. Which AWS service would be most suitable for querying and aggregating metrics from your application logs in real-time?

Concept tested:
Question 5 of 10
Objective Use infrastructure as code 3. Deployment (24%)

You're adopting Infrastructure as Code (IaC) to manage your AWS resources. What is the primary advantage of using CloudFormation templates?

Concept tested:
Question 6 of 10
Objective Apply least privilege 2. Security (26%)

When designing a system where developers need database access, how should permissions be handled to adhere to the principle of least privilege?

Concept tested:
Question 7 of 10
Objective Apply security; permission; access decisions 1. Development with AWS Services (32%)

A development team is migrating a monolithic application to a microservices architecture. To proactively identify and address security vulnerabilities across these newly decoupled services, what should they implement first?

Concept tested:
Question 8 of 10
Objective Optimize performance 4. Troubleshooting and Optimization (18%)

You are troubleshooting slow response times for an e-commerce application hosted within a VPC. You suspect network latency is contributing to the issue. What is the most effective initial step to diagnose and optimize network performance?

Concept tested:
Question 9 of 10
Objective Prepare application artifacts 3. Deployment (24%)

Your application experiences performance degradation in production. To accurately diagnose and reproduce the issue, you decide to create a test environment. What is the most critical factor to consider when configuring this environment?

Concept tested:
Question 10 of 10
Objective Apply message; api; queue decisions 1. Development with AWS Services (32%)

A company is experiencing intermittent failures in their application due to spikes in incoming requests. They want to implement a mechanism to prevent overload and ensure stability. What AWS service should they use to achieve this?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
DVA-C02 Pro $4.99 one-time

Unlock all 200 AWS Developer Associate questions, explanations, review tools, and exam-style practice.

50 Exam Practice Test $1.99 one-time

A 50-question DVA-C02 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

AWS Access Bundle $6.99/month

AWS practitioner, architect, and machine learning practice in one monthly unlock.

What’s includedAWS AI Practitioner, AWS Cloud Practitioner, AWS Developer Associate, AWS ML Engineer Associate, AWS SAA-C03

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full DVA-C02 bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily DVA-C02 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily AWS Developer Associate set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 You’ve identified that an S3 bucket is publicly accessible, containing sensitive PII data. Which service would be the most effective tool for proactively discovering and protecting this data within Amazon S3?

Answer choices

  1. A. Amazon Macie for identifying and protecting sensitive data.
  2. B. Amazon CloudWatch for monitoring S3 bucket metrics.
  3. C. AWS CloudTrail for monitoring API calls.
  4. D. AWS Config for defining and enforcing S3 bucket access policies.

Correct answer

Amazon Macie for identifying and protecting sensitive data.

Amazon Macie is designed to automatically discover and protect sensitive data, such as PII, within S3 buckets, providing proactive data protection. It analyzes data and identifies potential risks, enabling remediation actions.

Wrong-answer review

  • B. Amazon CloudWatch for monitoring S3 bucket metrics.: CloudWatch monitors metrics but doesn't actively identify or protect sensitive data within S3 buckets, lacking the data discovery capabilities needed.
  • C. AWS CloudTrail for monitoring API calls.: CloudTrail tracks API calls but doesn't analyze the data itself to identify sensitive information or enforce data protection policies.
  • D. AWS Config for defining and enforcing S3 bucket access policies.: AWS Config defines and enforces policies, but it doesn't automatically discover and protect sensitive data within S3 buckets, requiring manual configuration.

Extra learning features

Why candidates miss this

The distractors ‘Amazon CloudWatch for monitoring S3 bucket metrics.’ and ‘AWS CloudTrail for monitoring API calls.’ are tempting because they focus on monitoring and logging, which are important aspects of security but don’t directly address the proactive identification and protection of sensitive data. The decisive clue is the explicit requirement to ‘discover and protect’ the data, indicating a need for an active solution rather than passive monitoring. Likely wrong answer: Amazon CloudWatch for monitoring S3 bucket metrics. Review focus: AWS Well-Architected Security Pillar

Objective/domain: 2. Security (26%)

Source: AWS Well-Architected Security Pillar

Question 2 Your organization requires automated rotation of encryption keys used to protect data at rest in Amazon S3. Which approach best aligns with this requirement and minimizes operational overhead?

Answer choices

  1. A. Use KMS keys and configure automatic key rotation
  2. B. Manually rotate keys and update S3 bucket policies
  3. C. Implement a custom script to encrypt and decrypt data
  4. D. Store encryption keys directly in the application code

Correct answer

Use KMS keys and configure automatic key rotation

Objective/domain: 2. Security (26%)

Source: AWS Well-Architected Framework

Question 3 Your team is developing a REST API secured by an AWS Lambda authorizer. To control access to the API, you need to implement a mechanism that allows you to define custom authorization logic. What is the recommended approach?

Answer choices

  1. A. Utilize API keys and rate limits to restrict access.
  2. B. Leverage IAM roles to grant permissions to specific users.
  3. C. Configure a Lambda function to perform authentication and authorization.
  4. D. Implement a custom authentication protocol within the API Gateway configuration.

Correct answer

Configure a Lambda function to perform authentication and authorization.

Objective/domain: 1. Development with AWS Services (32%)

Source: Integrating Microservices by Using Serverless Services

Question 4 You’ve deployed a microservice that generates extensive logs. You want to analyze these logs to identify patterns and troubleshoot issues efficiently. Which AWS service would be most suitable for querying and aggregating metrics from your application logs in real-time?

Answer choices

  1. A. Amazon S3 for storing raw log files.
  2. B. Amazon Lambda for processing log events.
  3. C. Amazon CloudWatch Agent for collecting system metrics.
  4. D. Amazon CloudWatch Logs Insights for querying your logs.

Correct answer

Amazon CloudWatch Logs Insights for querying your logs.

Objective/domain: 4. Troubleshooting and Optimization (18%)

Source: AWS Well-Architected Framework

Question 5 You're adopting Infrastructure as Code (IaC) to manage your AWS resources. What is the primary advantage of using CloudFormation templates?

Answer choices

  1. A. Automatically scaling infrastructure based on application demand.
  2. B. Guaranteeing immediate and consistent infrastructure deployments.
  3. C. Eliminating the need for manual configuration entirely.
  4. D. Providing a single source of truth and enabling version control.

Correct answer

Providing a single source of truth and enabling version control.

Objective/domain: 3. Deployment (24%)

Source: AWS Well-Architected Framework

Question 6 When designing a system where developers need database access, how should permissions be handled to adhere to the principle of least privilege?

Answer choices

  1. A. Use AWS managed policies for common roles and remove unnecessary permissions.
  2. B. Grant all developers full administrative access for ease of use.
  3. C. Implement a single IAM user with broad database access for centralized control.
  4. D. Assign developers individual IAM users with extensive permissions for accountability.

Correct answer

Use AWS managed policies for common roles and remove unnecessary permissions.

Objective/domain: 2. Security (26%)

Source: AWS Well-Architected Security Pillar

Question 7 A development team is migrating a monolithic application to a microservices architecture. To proactively identify and address security vulnerabilities across these newly decoupled services, what should they implement first?

Answer choices

  1. A. Implement web application penetration testing after initial deployment.
  2. B. Set up a security monitoring service like AWS Security Hub.
  3. C. Configure a centralized authentication service for all microservices.
  4. D. Immediately deploy all microservices to a staging environment for testing.

Correct answer

Set up a security monitoring service like AWS Security Hub.

Objective/domain: 1. Development with AWS Services (32%)

Source: AWS Well-Architected Framework

Question 8 You are troubleshooting slow response times for an e-commerce application hosted within a VPC. You suspect network latency is contributing to the issue. What is the most effective initial step to diagnose and optimize network performance?

Answer choices

  1. A. Implement network monitoring tools to analyze traffic patterns and identify bottlenecks.
  2. B. Increase the maximum transmission unit (MTU) size for all network interfaces.
  3. C. Disable VPC Flow Logs to reduce storage costs.
  4. D. Manually adjust routing tables to optimize traffic flow.

Correct answer

Implement network monitoring tools to analyze traffic patterns and identify bottlenecks.

Objective/domain: 4. Troubleshooting and Optimization (18%)

Source: AWS Well-Architected Framework

Question 9 Your application experiences performance degradation in production. To accurately diagnose and reproduce the issue, you decide to create a test environment. What is the most critical factor to consider when configuring this environment?

Answer choices

  1. A. Using a simplified environment with minimal resources to reduce testing costs.
  2. B. Ensuring the test environment closely mirrors the production environment's scaling settings, resource quotas, and resiliency design.
  3. C. Focusing solely on testing the application's core functionality without simulating production load.
  4. D. Using a static environment configuration to avoid complexity.

Correct answer

Ensuring the test environment closely mirrors the production environment's scaling settings, resource quotas, and resiliency design.

Objective/domain: 3. Deployment (24%)

Source: AWS Well-Architected Framework

Question 10 A company is experiencing intermittent failures in their application due to spikes in incoming requests. They want to implement a mechanism to prevent overload and ensure stability. What AWS service should they use to achieve this?

Answer choices

  1. A. AWS Lambda
  2. B. Amazon SQS
  3. C. Amazon SNS
  4. D. Amazon API Gateway

Correct answer

Amazon API Gateway

Objective/domain: 1. Development with AWS Services (32%)

Source: AWS Well-Architected Framework

Where to go after the daily web set

How are AWS Developer Associate questions generated?

dotCreds builds AWS Developer Associate practice questions from public exam objectives and AWS certification and documentation references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start AWS Developer Associate practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.