All certifications / Developer Associate / Lessons
Developer Associate DVA-C02 lessons
Study Developer Associate for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Developer Associate study planA week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Domain 1: Development with AWS Services
- Architectural patterns: event-driven, microservices, fan-out, choreography vs orchestration, loosely coupled and stateless designs
- Resilient code: retries with exponential backoff and jitter, idempotency, timeouts, handling partial failures and dead-letter queues
- Messaging and streaming: SQS standard vs FIFO (message groups, deduplication, visibility timeout, long polling), SNS fan-out, EventBridge rules and Scheduler, Kinesis Data Streams
- AWS Step Functions: Standard vs Express workflows, retry/catch, task tokens for callbacks
- Calling AWS services with the SDKs and CLI: credential provider chain, pagination, waiters, error handling
- Lambda configuration: memory, timeout (15-minute max), ephemeral /tmp storage, environment variables, layers, concurrency, VPC access
- Lambda invocation models: synchronous, asynchronous (retries, destinations, DLQs) and event source mappings (SQS, Kinesis, DynamoDB Streams, partial batch responses)
- Lambda coding practices: initializing SDK clients and connections outside the handler, reading events, returning API Gateway proxy responses
- DynamoDB: partition and sort keys, Query vs Scan, LSI vs GSI, RCU/WCU math, consistency models, condition expressions, TTL, Streams, DAX
- Amazon S3 from code: multipart upload, storage classes and lifecycle, event notifications
- Caching strategies with ElastiCache: lazy loading, write-through, TTLs; choosing between SQL, NoSQL and in-memory stores
Domain 2: Security
- IAM for applications: execution roles, instance profiles, ECS task roles, least-privilege policies, policy evaluation (explicit deny wins)
- Resource-based policies: Lambda permissions for S3/SNS/API Gateway, S3 bucket policies, KMS key policies
- Cross-account access with STS AssumeRole and trust policies; temporary credentials
- Amazon Cognito: user pools (sign-up, sign-in, ID/access/refresh tokens) vs identity pools (temporary AWS credentials)
- API Gateway authorization: IAM (SigV4), Cognito user pool authorizers, Lambda authorizers, API keys and usage plans
- Encryption at rest: SSE-S3, SSE-KMS, SSE-C, S3 Bucket Keys, client-side encryption with the AWS Encryption SDK
- AWS KMS: customer managed vs AWS managed keys, envelope encryption with GenerateDataKey, 4 KB Encrypt limit, cross-account key use
- Encryption in transit: TLS, ACM certificates (us-east-1 for CloudFront), enforcing aws:SecureTransport
- Secrets and configuration: Secrets Manager (rotation) vs Systems Manager Parameter Store (SecureString, tiers)
- Keeping sensitive data out of code and logs: default credential chain, no hardcoded keys, CloudWatch Logs data protection masking
- Presigned URLs for temporary S3 access; IAM Access Analyzer for least privilege
Domain 3: Deployment
- Preparing artifacts: .zip packages vs container images in ECR, Lambda layers, dependency packaging, CodeArtifact
- AWS SAM: template structure, sam build, sam deploy --guided, sam local invoke / start-api, samconfig.toml
- CloudFormation: templates, parameters, outputs and exports, Fn::ImportValue, change sets, packaging local artifacts to S3
- AWS CDK basics: constructs, cdk bootstrap, cdk synth, cdk deploy
- Lambda versions and aliases; weighted aliases; CodeDeploy canary, linear and all-at-once traffic shifting with alarm rollback
- API Gateway stages, stage variables, deployments, mock integrations, canary releases
- Elastic Beanstalk deployment policies: all at once, rolling, rolling with additional batch, immutable, traffic splitting, blue/green URL swap
- CodePipeline stages and actions, manual approvals; CodeBuild buildspec phases and artifacts
- CodeDeploy appspec.yml lifecycle hooks for EC2, Lambda and ECS; the CodeDeploy agent
- Testing in development environments: unit tests in CI, integration tests against deployed stages, AppConfig feature flags and gradual configuration rollout
Domain 4: Troubleshooting and Optimization
- Root cause analysis with CloudWatch Logs, Logs Insights queries, metrics and dashboards
- Common Lambda errors: throttling (429), timeouts, AccessDenied from the execution role, malformed proxy responses (502), API Gateway 504 integration timeouts
- AWS X-Ray: segments, subsegments, annotations vs metadata, sampling, active tracing, the X-Ray daemon/CloudWatch agent
- Custom metrics: PutMetricData, CloudWatch embedded metric format, high-resolution metrics
- CloudWatch alarms with SNS notifications; structured logging and correlation IDs
- Lambda performance: memory/CPU tuning, cold starts, provisioned concurrency, reserved concurrency
- Stream and queue troubleshooting: Kinesis IteratorAge, parallelization factor, SQS dead-letter queues and redrive
- DynamoDB optimization: hot partitions, key design, on-demand vs provisioned capacity, adaptive capacity
- Caching for performance: API Gateway stage caching, CloudFront, ElastiCache, DAX