Skip to content

Security Questions

Practice questions for Security topic in AWS Certified Developer - Associate. 52 questions covering this domain.

52 questions13 easy25 medium14 hard
Q1
medium

A platform team wants developers to have only the minimum permissions required for their workloads and to apply fine-grained access controls to AWS re...

Q2
easy

A security engineer needs to create and control cryptographic keys used to encrypt application data. Which AWS service is the best fit?

Q3
medium

A compliance reviewer asks whether a team is protecting data when it is stored and also while it moves over the network. Which pair of concepts should...

Q4
hard

Application logs are exposing unredacted customer PII. Which action best aligns with the DVA-C02 security guidance?

Q5
medium

A web application needs to authenticate users and then authorize API calls using tokens passed by the client. Which AWS service is the best match for ...

Q6
hard

A microservices application currently shares long-lived credentials across services to call AWS APIs. What is the best AWS-aligned improvement?

Q7
easy

A development team needs a managed AWS service to centrally store database passwords, API keys, and other secrets, with built-in rotation support. Whi...

Q8
medium

A security team wants encryption keys to be rotated automatically on an ongoing basis. Which AWS capability should they use?

Q9
hard

An audit finds that a Lambda function stores database passwords in environment variables. What is the best remediation?

Q10
medium

An application in one AWS account needs temporary access to resources in another AWS account without storing long-term credentials. What is the best A...

Q11
easy

A company wants secure sign-in and access control for application users, with support for federation and social identity providers. Which AWS service ...

Q12
hard

A SaaS company needs tenant-based identity stores, federation options, and role-based access to AWS services for its customer-facing application. Whic...

Q13
medium

A payment application must ensure that plaintext is encrypted before it is sent to an AWS service so the service never receives unencrypted data. Whic...

Q14
hard

A developer must allow only specific source IP ranges to invoke an Amazon API Gateway REST API while keeping it public on the internet. Which mechanis...

Q15
easy

Which AWS service issues, deploys, and renews public TLS/SSL certificates for use with CloudFront, ALB, and API Gateway at no charge?

Q16
medium

A web app must allow JavaScript on https://example.com to call an Amazon API Gateway REST API hosted on a different domain. Which API Gateway capabili...

Q17
medium

A REST API needs to validate JSON Web Tokens (JWTs) issued by an OIDC provider before invoking the Lambda backend. Which API Gateway feature should be...

Q18
easy

Which AWS Identity and Access Management policy element specifies the actions, resources, and conditions that a permission applies to?

Q19
hard

A developer must allow a third-party SaaS to assume an IAM role in the customer's AWS account using a shared identifier supplied by the SaaS to mitiga...

Q20
medium

A developer must allow Lambda to write to an S3 bucket without storing access keys in code. Which approach should they use?

Sign in to see all 52 questions

Create a free account to browse all questions — completely free during our launch phase.