StudyToCert

All certifications / Developer Associate / Cheat sheet

Developer Associate DVA-C02 cheat sheet

Every exam tip and key term from the free Developer Associate lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Development with AWS Services (32%)

Exam tips

Key terms

Loose coupling
Designing components so they interact through an intermediary or stable contract, letting each fail, scale and deploy independently.
Fan-out
Delivering one published message to many subscribers in parallel, for example an SNS topic with several SQS queue subscriptions.
Choreography
Coordination where each service reacts to events and emits new ones with no central controller.
Orchestration
Coordination where a central workflow engine, such as Step Functions, invokes each step and manages state and errors.
Stateless service
A service that keeps no client state between requests, storing it externally so any instance can handle any request.
Exponential backoff
A retry strategy where the wait between attempts grows multiplicatively, reducing pressure on a struggling service.
Jitter
Random variation added to retry delays so many clients do not retry in synchronized waves.
Idempotency
The property that repeating an operation produces the same result as doing it once, making retries and duplicate deliveries safe.
Poison message
A message that fails processing every time it is received and would loop forever without a dead-letter queue.
Dead-letter queue (DLQ)
A queue that receives messages or events that failed processing after a configured number of attempts, for later inspection.
Visibility timeout
The period after an SQS message is received during which it is hidden from other consumers; it reappears if not deleted in time.
Message group ID
The FIFO queue attribute that defines an ordered group; messages in the same group are processed strictly in order.
Long polling
A ReceiveMessage call that waits up to 20 seconds for messages, reducing empty responses and cost.
Event pattern
The JSON filter in an EventBridge rule that selects which events are sent to the rule's targets.
Shard
The unit of capacity and ordering in a Kinesis data stream; records with the same partition key go to the same shard.
Amazon States Language (ASL)
The JSON-based language used to define Step Functions state machines.
Standard workflow
A Step Functions workflow type for long-running (up to one year), exactly-once, fully audited executions.
Express workflow
A Step Functions workflow type for high-volume, short (up to five minutes) executions, logged to CloudWatch Logs.
Task token
A token Step Functions passes to an external process in the Wait for Callback pattern; the workflow resumes when SendTaskSuccess or SendTaskFailure is called with it.
Default credential provider chain
The ordered list of places an SDK or the CLI looks for credentials, ending with the role credentials of the compute environment.
Paginator
An SDK helper that automatically follows continuation tokens to return every page of a list API's results.
Waiter
An SDK or CLI helper that polls until a resource reaches a specified state or a maximum number of attempts is reached.
SigV4
Signature Version 4, the process that signs AWS API requests with credentials so the service can authenticate them.
Timeout
The maximum run time for one Lambda invocation, configurable from 1 second to 15 minutes, with a default of 3 seconds.
Ephemeral storage (/tmp)
Per-environment scratch disk for a Lambda function, 512 MB by default and configurable up to 10,240 MB, not durable.
Layer
A versioned .zip archive of shared code or dependencies that many functions can reference; each function can include up to five layers.
Reserved concurrency
A setting that both guarantees and caps the number of concurrent executions for a function.
Synchronous invocation
The caller waits for the function's response; retries are the caller's responsibility.
Asynchronous invocation
Lambda queues the event, returns 202 immediately, and retries failures itself before sending them to a DLQ or destination.
Lambda destination
A target (SQS, SNS, Lambda, EventBridge, or S3 for failures) that receives a record of an asynchronous or stream invocation's success or failure.
Event source mapping
A Lambda resource that polls a queue or stream and invokes the function with batches of records.
ReportBatchItemFailures
An event source mapping setting that lets the function return only the failed records so successful ones are not retried.
Handler
The function Lambda calls for each invocation, receiving the event and the context object.
Init phase
The part of a cold start where Lambda loads code and runs initialization outside the handler, done once per execution environment.
Lambda proxy integration
An API Gateway integration that passes the full HTTP request to Lambda and expects a response with statusCode, headers and a string body.
Context object
The second handler argument, exposing the request ID, function name, memory limit and remaining execution time.
Partition key
The key attribute DynamoDB hashes to decide which partition stores an item.
Global secondary index (GSI)
An index with its own partition and sort key, addable any time, with separate capacity and eventually consistent reads only.
Local secondary index (LSI)
An index sharing the table's partition key with an alternate sort key; created only with the table.
Read capacity unit (RCU)
One strongly consistent read per second, or two eventually consistent reads, of an item up to 4 KB.
Write capacity unit (WCU)
One write per second of an item up to 1 KB.
Multipart upload
Uploading an object as separately uploaded parts that S3 assembles; required above 5 GB and recommended for large files.
Lifecycle rule
A bucket configuration that transitions objects to other storage classes or expires them after set periods.
S3 Intelligent-Tiering
A storage class that automatically moves objects between access tiers based on how often they are accessed.
Event notification
An S3 feature that sends object-level events to Lambda, SQS, SNS or EventBridge, optionally filtered by prefix and suffix.
Lazy loading (cache-aside)
A strategy that populates the cache only on a cache miss, after reading from the database.
Write-through
A strategy that writes to the cache every time the database is updated, keeping cached data current.
TTL (time to live)
An expiry time on a cache key after which it is removed and reloaded on the next read.
Cache hit ratio
The proportion of reads served from the cache; a low ratio suggests poor keys, short TTLs or too small a cache.

Domain 2: Security (26%)

Exam tips

Key terms

Execution role
The IAM role a Lambda function assumes to get temporary credentials for calling other AWS services.
Instance profile
A container that attaches an IAM role to an EC2 instance so applications on it receive temporary credentials.
ECS task role
The IAM role whose permissions the application containers in an ECS task use, distinct from the task execution role.
Explicit deny
A policy statement with Effect Deny that overrides any Allow for matching requests.
Least privilege
Granting only the specific actions and resources needed to perform a task.
Resource-based policy
A policy attached to a resource that names the principals allowed to access it.
Function policy
The resource-based policy on a Lambda function that authorizes services or accounts to invoke it.
Bucket policy
A resource-based policy on an S3 bucket controlling access and enforcing conditions for requests to it.
Key policy
The mandatory resource-based policy on a KMS key; IAM policies only work if it allows them.
Confused deputy
A situation where a trusted service is tricked into acting for the wrong party, prevented with SourceArn and SourceAccount conditions.
Trust policy
The resource-based policy on an IAM role that specifies which principals may assume it.
AssumeRole
The STS API that returns temporary credentials for a role to a trusted caller.
Temporary credentials
An access key ID, secret access key and session token that expire after a set duration.
External ID
A value required in a trust policy condition that third parties must supply when assuming a role, preventing confused deputy attacks.
Role chaining
Using credentials from one assumed role to assume another role; sessions are limited to one hour.
User pool
A Cognito user directory that handles sign-up and sign-in and issues JWT ID, access and refresh tokens.
Identity pool
A Cognito component that exchanges identity provider tokens for temporary AWS credentials via IAM roles.
ID token
A JWT containing claims about the authenticated user's identity.
Access token
A JWT containing scopes and groups, used to authorize API requests.
Refresh token
A long-lived token used to obtain new ID and access tokens without re-authenticating.
IAM authorization
API Gateway authorization that requires SigV4-signed requests and an IAM policy allowing execute-api:Invoke.
Cognito user pool authorizer
An API Gateway authorizer that validates JWTs issued by a Cognito user pool without custom code.
Lambda authorizer
A function that receives a token or request parameters and returns an IAM policy allowing or denying the request.
Usage plan
An API Gateway configuration that applies throttling and quota limits to the API keys associated with it.
SSE-S3
Server-side encryption with keys fully managed by S3, using AES-256; the default for new objects.
SSE-KMS
Server-side encryption using a KMS key, providing CloudTrail auditing and key-policy control.
SSE-C
Server-side encryption with a customer-provided key sent in each HTTPS request and not stored by S3.
S3 Bucket Key
A bucket-level key derived from KMS that reduces the number of KMS calls, cost and throttling for SSE-KMS.
AWS Encryption SDK
A client-side library that performs envelope encryption so data is encrypted before it leaves the application.
Customer managed key
A KMS key you create and control, including its key policy, rotation and cross-account access.
AWS managed key
A KMS key created by an AWS service for your account, with a fixed key policy you cannot change.
Envelope encryption
Encrypting data with a data key and then encrypting that data key with a KMS key.
GenerateDataKey
A KMS API that returns a data key in plaintext and encrypted forms for local encryption.
Encryption context
Non-secret key-value pairs bound to a KMS encryption operation that must match on decryption.
TLS
Transport Layer Security, the protocol that encrypts and authenticates network connections such as HTTPS.
AWS Certificate Manager (ACM)
A service that provisions, deploys and automatically renews TLS certificates for integrated AWS services.
aws:SecureTransport
A global IAM condition key that is true when a request was made over TLS.
TLS termination
The point where encrypted traffic is decrypted, such as a load balancer or CloudFront.
Secrets Manager rotation
A scheduled process in which a Lambda function replaces a secret's credential in both the secret and the target service.
SecureString
A Parameter Store parameter type whose value is encrypted with a KMS key.
Parameter hierarchy
Path-style parameter names that group settings and allow retrieval and IAM control by path.
Advanced parameter
A paid Parameter Store tier with larger values and parameter policies such as expiration.
Staging label
A label such as AWSCURRENT or AWSPENDING that marks which version of a secret is in use.
Hardcoded credentials
Access keys or passwords written directly into code or artifacts, easily leaked and hard to rotate.
Data protection policy
A CloudWatch Logs policy that detects and masks sensitive data in log events using data identifiers.
Managed data identifier
A predefined pattern for a sensitive data type, such as credit card numbers, used by CloudWatch Logs data protection.
logs:Unmask
The IAM permission that lets a principal view masked sensitive values in CloudWatch Logs.
Presigned URL
A URL signed with an identity's credentials that grants temporary access to a specific S3 operation on one object.
Presigned POST
A signed form policy allowing browser uploads to S3 with conditions such as size limits and key prefixes.
IAM Access Analyzer
A service that finds externally shared and unused access, validates policies, and generates least-privilege policies from activity.
Zone of trust
The account or organization that Access Analyzer treats as internal when reporting external access.

Domain 3: Deployment (24%)

Exam tips

Key terms

.zip deployment package
An archive of function code and dependencies deployed to a managed Lambda runtime.
Container image function
A Lambda function packaged as an OCI image up to 10 GB, stored in Amazon ECR.
Amazon ECR
Elastic Container Registry, AWS's managed registry for container images.
AWS CodeArtifact
A managed package repository that proxies public registries and hosts private packages for build tools.
Transform: AWS::Serverless-2016-10-31
The template declaration that makes CloudFormation process SAM resource types.
sam build
The SAM CLI command that installs dependencies and prepares deployment artifacts.
sam deploy --guided
An interactive deployment that prompts for settings and saves them to samconfig.toml.
sam local start-api
Runs a local emulation of API Gateway routes backed by functions running in Docker.
SAM policy template
A named, parameterized IAM policy, such as DynamoDBReadPolicy, used in a function's Policies property.
Stack
A set of AWS resources created and managed together from one CloudFormation template.
Export
An output value made available to other stacks in the same Region, read with Fn::ImportValue.
Change set
A preview of the changes CloudFormation will make to a stack, which you review and then execute.
aws cloudformation package
Uploads local artifacts referenced by a template to S3 and outputs a template with S3 locations.
CAPABILITY_IAM
An acknowledgment required when deploying a template that creates or modifies IAM resources.
Construct
The basic CDK building block representing one or more AWS resources, arranged in a tree under an App.
L2 construct
A higher-level CDK class with sensible defaults and helper methods, such as s3.Bucket.
cdk bootstrap
Creates the CDKToolkit stack with an asset bucket, ECR repository and deployment roles in an account and Region.
cdk synth
Runs the CDK app and produces CloudFormation templates in the cdk.out directory.
$LATEST
The mutable, unpublished version of a Lambda function that reflects the most recent code and configuration edits.
Version
An immutable, numbered snapshot of a Lambda function's code and configuration.
Alias
A named pointer to a function version, optionally weighted between two versions, with its own ARN.
Canary deployment
A traffic shift that sends a small percentage to the new version first, then the rest after a wait.
Linear deployment
A traffic shift that moves equal percentages to the new version at regular intervals.
Deployment
A snapshot of a REST API's configuration that must be created for changes to go live on a stage.
Stage
A named reference to a deployment, with its own URL and settings such as caching, throttling and logging.
Stage variable
A name-value pair on a stage, referenced as ${stageVariables.name} in integrations and mapping templates.
Mock integration
An integration where API Gateway returns a response from a mapping template without calling a backend.
Canary release
A stage setting that routes a percentage of traffic to a new deployment before promotion.
Deployment policy
The Elastic Beanstalk setting that controls how a new application version is rolled onto an environment's instances.
Rolling with additional batch
A policy that launches an extra batch of instances first so capacity never drops during a rolling deployment.
Immutable deployment
A policy that deploys to a fresh set of instances and swaps them in only after they are healthy.
Swap environment URLs
A blue/green technique that exchanges the CNAMEs of two Beanstalk environments to move production traffic.
Action
A task within a stage, such as a source fetch, CodeBuild build, deployment or manual approval.
Artifact
Files produced by one pipeline action and consumed by another, stored in the pipeline's S3 bucket.
buildspec.yml
The YAML file defining CodeBuild's environment, phases, artifacts, reports and cache.
Manual approval
A pipeline action that pauses execution until an authorized person approves or rejects it.
appspec.yml
The CodeDeploy application specification file describing files to deploy and lifecycle hook scripts or functions.
CodeDeploy agent
Software on EC2 or on-premises instances that pulls revisions from CodeDeploy and runs lifecycle hooks.
Lifecycle event hook
A point in a deployment where CodeDeploy runs your script or Lambda function, such as AfterInstall.
AfterAllowTestTraffic
An ECS deployment hook that runs after the test listener sends traffic to the new task set, before production traffic shifts.
Unit test
A fast, isolated test of a single piece of logic with external dependencies mocked.
Integration test
A test against deployed resources to verify real permissions, triggers and service interactions.
Feature flag
A configuration switch that turns functionality on or off at runtime without redeploying code.
AppConfig deployment strategy
Settings controlling how quickly a configuration change rolls out and how long it bakes before completing.

Domain 4: Troubleshooting and Optimization (18%)

Exam tips

Key terms

Log group
A CloudWatch Logs container for log streams that share retention, encryption and access settings.
CloudWatch Logs Insights
An interactive query service for searching and aggregating log data with a pipe-based query language.
Metric filter
A rule that extracts metric values from matching log events so they can be graphed and alarmed on.
Dimension
A name-value pair that identifies a specific metric series, such as FunctionName=checkout.
TooManyRequestsException (429)
The error returned when a Lambda invocation is throttled because no concurrency is available.
Task timed out
The log message Lambda writes when an invocation exceeds its configured timeout.
Malformed Lambda proxy response
An API Gateway error (returned to clients as 502) when a proxy integration's function output has the wrong format.
Integration timeout
The maximum time API Gateway waits for a backend response, 29 seconds by default, after which it returns 504.
Segment
The record of work done by one service for a traced request, including timing, request details and errors.
Subsegment
A finer-grained part of a segment, such as one downstream call or a timed block of code.
Annotation
An indexed key-value pair on a segment that can be used in filter expressions to search traces.
Metadata
Non-indexed key-value data of any type stored with a segment for viewing but not searching.
Sampling rule
A rule that sets how many requests of a given kind are traced, using a reservoir and a fixed rate.
Namespace
A container for CloudWatch metrics, such as MyShop/Checkout; the AWS/ prefix is reserved for AWS services.
PutMetricData
The CloudWatch API for publishing custom metric data points or statistic sets.
Embedded metric format (EMF)
A structured JSON log format from which CloudWatch Logs automatically extracts metrics.
High-resolution metric
A custom metric stored at one-second granularity by setting StorageResolution to 1.
Metric alarm
A CloudWatch alarm that changes state when a metric or expression crosses a threshold for a set number of periods.
Datapoints to alarm
The number of breaching data points within the evaluation periods required to trigger ALARM (M out of N).
Composite alarm
An alarm whose state is computed from a rule combining other alarms' states.
Structured logging
Writing log entries as consistent machine-readable fields, usually JSON.
Correlation ID
A unique identifier propagated through all services handling a request so their logs can be linked.
Cold start
The added latency when Lambda creates and initializes a new execution environment before running the handler.
Init Duration
The REPORT log field showing how long initialization took for an invocation that had a cold start.
Provisioned concurrency
Pre-initialized execution environments on a version or alias that remove cold starts, billed while configured.
Reserved concurrency
A free setting that guarantees and caps a function's concurrent executions.
Lambda SnapStart
A feature for supported runtimes that resumes new environments from a snapshot of an initialized one to shorten cold starts.
IteratorAge
The metric showing how old the records being processed from a stream are, indicating how far behind a consumer is.
Parallelization factor
An event source mapping setting (1 to 10) for concurrent batches per shard, preserving order per partition key.
Enhanced fan-out
A Kinesis feature that gives each registered consumer dedicated read throughput per shard.
maxReceiveCount
The number of times an SQS message can be received before the redrive policy moves it to the DLQ.
DLQ redrive
Moving messages from a dead-letter queue back to a source queue for reprocessing after a fix.
Hot partition
A partition receiving a disproportionate share of requests, causing throttling despite unused table capacity.
Write sharding
Adding a random or calculated suffix to partition keys to spread writes across more partitions.
On-demand capacity
A DynamoDB mode billed per request that scales automatically without capacity planning.
Adaptive capacity
DynamoDB's automatic reallocation of throughput to busier partitions and isolation of frequently accessed items.
Burst capacity
Unused capacity DynamoDB briefly retains to absorb short traffic spikes.
API Gateway stage cache
A per-stage REST API cache that returns stored integration responses for a TTL of up to 3,600 seconds.
Cache key
The request attributes used to decide whether a cached response matches a new request.
CloudFront invalidation
A request that removes objects from CloudFront edge caches before their TTL expires.
DynamoDB Accelerator (DAX)
An API-compatible in-memory cache for DynamoDB offering microsecond eventually consistent reads.
Study Developer Associate for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the Developer Associate study plan