Explore / Careers & Certification
AWS Certified Developer - Associate (DVA-C02) Exam Prep

Work through every domain, task and in-scope service of the AWS Certified Developer - Associate (DVA-C02) exam guide v2.1 at developer depth, with SDK and CLI calls, IAM policies, SAM templates, buildspec and appspec files, and original scenario questions with every distractor explained. Independent
Expert · 61 levels · 2 free · Created Oct 2026 · Professionally curated by levelupwith.com
What's inside
- Level 1: Exam Briefing, AWS CLI, SDKs and CloudShellFree
[All domains – exam orientation] States that this course is independent of AWS and promises no pass, then covers the DVA-C02 format (65 questions with 50 scored and 15 unscored, 130 minutes, scaled pass mark 720 of 1,000, multiple choice and multiple response, no penalty for guessing), the four weighted domains, and the AWS CLI, AWS SDKs and AWS CloudShell used in every later level. - Level 2: Architectural Patterns and CouplingFree
[Development with AWS Services – Task 1: Develop code for applications hosted on AWS] Covers the vocabulary of Skills 1.1.1 to 1.1.4: event-driven, microservices, monolithic, choreography, orchestration and fanout patterns, stateful versus stateless, tightly versus loosely coupled components, and synchronous versus asynchronous patterns. - Level 3: Calling AWS Services with APIs and SDKs
[Development with AWS Services – Task 1: Develop code for applications hosted on AWS] Covers Skill 1.1.9: how an SDK or AWS CLI call becomes a signed HTTPS request to a service endpoint, how credentials are resolved, and how to handle pagination, waiters and service error responses in code. - Level 4: Where Code Runs: EC2, Elastic Beanstalk, ECS, EKS
[Development with AWS Services – Task 1: Develop code for applications hosted on AWS] Explains from first principles the non-Lambda compute services a developer deploys to — Amazon EC2, AWS Elastic Beanstalk, Amazon ECS and Amazon EKS — and what each asks the developer to supply and configure. - Level 5: Building APIs with Amazon API Gateway
[Development with AWS Services – Task 1: Develop code for applications hosted on AWS] Covers Skill 1.1.6 with Amazon API Gateway: creating, extending and maintaining APIs, including integration types, stages, request/response transformations, enforcing validation rules and overriding status codes. - Level 6: GraphQL APIs with AWS AppSync
[Development with AWS Services – Task 1: Develop code for applications hosted on AWS] Extends Skill 1.1.6 to AWS AppSync: a managed GraphQL API whose schema, resolvers and data sources let clients fetch exactly the fields they need and receive real-time updates. - Level 7: Queues in Code: Amazon SQS
[Development with AWS Services – Task 1: Develop code for applications hosted on AWS] Covers the queue half of Skill 1.1.8, writing code to use messaging services, with Amazon SQS: sending, receiving and deleting messages, and the settings that control delivery behaviour. - Level 8: Publish/Subscribe and Fanout: Amazon SNS
[Development with AWS Services – Task 1: Develop code for applications hosted on AWS] Covers the publish/subscribe half of Skill 1.1.8 with Amazon SNS: topics, subscriptions and protocols, and the SNS-to-SQS fanout pattern named in Skill 1.1.1. - Level 9: Event-Driven Patterns with Amazon EventBridge
[Development with AWS Services – Task 1: Develop code for applications hosted on AWS] Covers Skill 1.1.12: using Amazon EventBridge event buses, rules, event patterns and targets to implement event-driven, choreographed applications. - Level 10: Orchestration with AWS Step Functions
[Development with AWS Services – Task 1: Develop code for applications hosted on AWS] Teaches the orchestration pattern of Skill 1.1.1 at developer depth with AWS Step Functions: state machines written in Amazon States Language that coordinate services with built-in error handling. - Level 11: Handling Streaming Data with Amazon Kinesis
[Development with AWS Services – Task 1: Develop code for applications hosted on AWS] Covers Skill 1.1.10: handling streaming data with Amazon Kinesis Data Streams (shards, partition keys, producers and consumers) and delivery to stores with Amazon Data Firehose. - Level 12: Fault-Tolerant Code: Retries, Backoff, Circuit Breakers
[Development with AWS Services – Task 1: Develop code for applications hosted on AWS] Covers Skills 1.1.5 and 1.1.13: creating fault-tolerant and resilient application code, including retry logic, circuit breakers and error handling patterns for third-party service integrations. - Level 13: AWS Lambda Configuration and VPC Access
[Development with AWS Services – Task 2: Develop code for AWS Lambda] Covers Skills 1.2.1 and 1.2.2: how Lambda runs code, how to configure a function (memory, concurrency, timeout, runtime, handler, layers, extensions, environment variables), and how Lambda code reaches private resources in a VPC. - Level 14: Lambda Invocation Models and Event Sources
[Development with AWS Services – Task 2: Develop code for AWS Lambda] Covers Skills 1.2.5 and 1.2.7: integrating Lambda functions with AWS services through triggers and event source mappings, and using Lambda to process and transform data in near real time from queues and streams. - Level 15: Lambda Errors: Destinations and Dead-Letter Queues
[Development with AWS Services – Task 2: Develop code for AWS Lambda] Covers Skill 1.2.3: handling the event lifecycle and errors in code, including retry behaviour for each invocation type, Lambda Destinations and dead-letter queues. - Level 16: Testing Code with AWS SAM and Amazon Q Developer
[Development with AWS Services – Tasks 1 and 2] Covers Skills 1.1.7, 1.2.4 and 1.1.11: writing and running unit tests in development environments (for example, using AWS SAM), testing Lambda code with AWS services and tools, and using Amazon Q Developer to assist with development. - Level 17: Amazon DynamoDB Keys and Indexes
[Development with AWS Services – Task 3: Use data stores in application development] Covers Skills 1.3.1 and 1.3.4: Amazon DynamoDB from first principles — tables, items, partition and sort keys, why high-cardinality partition keys give balanced partition access, and local and global secondary indexes. - Level 18: DynamoDB in Code: Query vs Scan and Consistency
[Development with AWS Services – Task 3: Use data stores in application development] Covers Skills 1.3.2, 1.3.3 and 1.3.5: the differences between query and scan operations, strongly consistent and eventually consistent reads, and serializing and deserializing application objects to DynamoDB items. - Level 19: Relational, Cache and Specialised Data Stores
[Development with AWS Services – Task 3: Use data stores in application development] Covers Skills 1.3.6, 1.3.8 and 1.3.9: using and maintaining Amazon RDS and Amazon Aurora from application code, using data caching services with Amazon ElastiCache, and choosing specialised stores such as Amazon OpenSearch Service and Amazon Athena by access pattern. - Level 20: Amazon S3, EBS and EFS: Storage and Data Lifecycles
[Development with AWS Services – Task 3: Use data stores in application development] Covers Skill 1.3.7, managing data lifecycles, and completes Skill 1.3.6 for storage: Amazon S3 object operations and lifecycle rules, DynamoDB Time to Live, and when application code should use Amazon EBS block storage or Amazon EFS shared file storage instead. - Level 21: IAM Principals and Policy Anatomy
[Domain 2: Security – Task 1, Skill 2.1.6 Define permissions for IAM principals] Explains from first principles what an IAM principal is (user, role, AWS service, federated identity) and how to read and write a JSON identity-based policy with Effect, Action, Resource and Condition, using a least-privilege policy for an S3 bucket and a DynamoDB table as the worked example. - Level 22: Policy Evaluation: Deny, Resource Policies, Conditions
[Domain 2: Security – Task 1, Skill 2.1.6 Define permissions for IAM principals] Teaches how AWS decides allow or deny when several policies apply: explicit deny wins, default deny, identity-based versus resource-based policies (S3 bucket policies, SQS queue policies, Lambda resource-based policies), permissions boundaries, and condition keys and policy variables such as aws:SourceArn and ${aws:username}. - Level 23: Programmatic Access and Signed Calls to AWS
[Domain 2: Security – Task 1, Skills 2.1.3 Configure programmatic access to AWS and 2.1.4 Make authenticated calls to AWS services] Shows how the AWS CLI and SDKs find credentials (the default credential provider chain, named profiles, environment variables, EC2 instance profiles, ECS task roles, Lambda execution roles) and how every request is signed with Signature Version 4, including why long-term access keys in code are the wrong answer. - Level 24: Assuming IAM Roles with AWS STS
[Domain 2: Security – Task 1, Skill 2.1.5 Assume an IAM role] Covers AWS Security Token Service at developer depth: the sts:AssumeRole call, the role trust policy versus the permissions policy, temporary credentials and session duration, cross-account access with an external ID, role chaining limits, and get-caller-identity as the first debugging step. - Level 25: Federated Access with Identity Providers
[Domain 2: Security – Task 1, Skill 2.1.1 Use an identity provider to implement federated access] Explains federation from first principles: trusting an external identity provider through IAM using SAML 2.0 or OpenID Connect, the STS calls AssumeRoleWithSAML and AssumeRoleWithWebIdentity, and when to federate through IAM directly versus through Amazon Cognito. - Level 26: Amazon Cognito User Pools: Sign-In and Tokens
[Domain 2: Security – Task 1, Skills 2.1.1 Use an identity provider to implement federated access and 2.1.2 Secure applications by using bearer tokens] Teaches Amazon Cognito user pools as a user directory and OIDC identity provider: app clients, sign-up and sign-in flows, managed login, social and SAML sign-in through the pool, MFA, Lambda triggers, and the ID, access and refresh tokens the pool issues. - Level 27: Amazon Cognito Identity Pools: AWS Credentials for Users
[Domain 2: Security – Task 1, Skill 2.1.1 Use an identity provider to implement federated access] Contrasts identity pools with user pools: an identity pool exchanges a token from a user pool or other provider for temporary AWS credentials through STS, with authenticated and unauthenticated (guest) roles and role mapping, so a web or mobile app can call services such as S3 or DynamoDB directly. - Level 28: Bearer Tokens and API Gateway Authorizers
[Domain 2: Security – Task 1, Skill 2.1.2 Secure applications by using bearer tokens] Shows how an API verifies a JSON Web Token (signature, expiry, audience, scopes) and compares the ways to protect an Amazon API Gateway API: IAM authorization with Signature Version 4, Cognito user pool authorizers, Lambda authorizers, JWT authorizers on HTTP APIs, resource policies, API keys with usage plans, and AWS WAF in front for request filtering. - Level 29: Fine-Grained Authorization and Service-to-Service Auth
[Domain 2: Security – Task 1, Skills 2.1.7 Implement application-level authorization for fine-grained access control and 2.1.8 Handle cross-service authentication in microservice architectures] Covers authorizing inside the application: Cognito groups, custom claims and OAuth scopes, the Lambda authorizer's policy and context output, AWS AppSync authorization modes, and DynamoDB fine-grained access with dynamodb:LeadingKeys; then how microservices authenticate to each other with IAM roles and Signature Version 4, resource-based policies, and the OAuth client credentials grant. - Level 30: Encryption at Rest, in Transit, Client-Side, Server-Side
[Domain 2: Security – Task 2, Skills 2.2.1 Define encryption at rest and in transit and 2.2.3 Describe differences between client-side encryption and server-side encryption] Defines the four terms with concrete cases: TLS to AWS endpoints and enforcing it with aws:SecureTransport; the Amazon S3 server-side options SSE-S3, SSE-KMS, DSSE-KMS and SSE-C; encryption settings for EBS, EFS, RDS, Aurora, DynamoDB and SQS; and client-side encryption where data is encrypted before it leaves the application. - Level 31: AWS KMS Keys and Envelope Encryption
[Domain 2: Security – Task 2, Skill 2.2.4 Use encryption keys to encrypt or decrypt data] Teaches AWS Key Management Service at API depth: AWS owned, AWS managed and customer managed keys; Encrypt, Decrypt and ReEncrypt and their 4 KB limit; GenerateDataKey and envelope encryption for larger data; encryption context; the AWS Encryption SDK; and KMS request quotas with S3 Bucket Keys as the fix for throttling. - Level 32: KMS Key Policies, Cross-Account Use and Rotation
[Domain 2: Security – Task 2, Skills 2.2.6 Use encryption across account boundaries and 2.2.7 Enable and disable key rotation] Covers who may use a KMS key: the key policy as the root of access, IAM policies and grants, the kms:ViaService condition, sharing a customer managed key with another account (key policy plus the caller's IAM policy), and automatic versus on-demand versus manual key rotation and what each does to existing ciphertext. - Level 33: Certificates, AWS Private CA and SSH Keys
[Domain 2: Security – Task 2, Skills 2.2.2 Describe certificate management (for example, AWS Private CA) and 2.2.5 Generate certificates and SSH keys for development purposes] Explains what a TLS certificate proves, public certificates from AWS Certificate Manager attached to Elastic Load Balancing, CloudFront and API Gateway, private certificates from AWS Private CA for internal services, and generating self-signed certificates and EC2 key pairs for development work. - Level 34: Secrets Manager, Parameter Store and Encrypted Env Vars
[Domain 2: Security – Task 3, Skills 2.3.2 Encrypt environment variables that contain sensitive data and 2.3.3 Use secret management services to secure sensitive data] Compares AWS Secrets Manager (automatic rotation, cross-account resource policies, GetSecretValue) with AWS Systems Manager Parameter Store (String, StringList, SecureString, hierarchies, GetParametersByPath), covers how Lambda environment variables are encrypted with KMS including encryption helpers, and shows fetching and caching secrets at runtime instead of hard-coding them. - Level 35: Data Classification, Masking and Multi-Tenant Access
[Domain 2: Security – Task 3, Skills 2.3.1 Describe data classification, 2.3.4 Sanitize sensitive data, 2.3.5 Implement application-level data masking and sanitization and 2.3.6 Implement data access patterns for multi-tenant applications] Defines personally identifiable information (PII) and protected health information (PHI), then teaches keeping them out of logs, traces and error messages by sanitising inputs and masking outputs (including CloudWatch Logs data protection policies), and isolating tenants with tenant-scoped partition keys, IAM policy conditions and per-tenant credentials or keys. - Level 36: Lambda Deployment Packages: Zip, Layers, Images
[Domain 3: Deployment – Task 1, Skills 3.1.1 Manage the dependencies of the code module within the package and 3.1.2 Organize files and a directory structure for application deployment; Task 4, Skill 3.4.1 Describe Lambda deployment packaging options] Covers the three ways to ship Lambda code: .zip archives (direct upload versus from S3, size limits, handler path and folder layout), Lambda layers for shared dependencies, and container images, with the trade-offs of each. - Level 37: Container Images, Amazon ECR and Resource Requirements
[Domain 3: Deployment – Task 1, Skills 3.1.1 Manage the dependencies of the code module (container images) and 3.1.4 Apply application requirements for resources (for example, memory, cores)] Teaches preparing a container artifact: building and tagging an image, authenticating Docker to Amazon ECR and pushing, image tag immutability, image scanning and lifecycle policies, then declaring CPU and memory in an ECS task definition and memory and ephemeral storage on a Lambda function. - Level 38: Dependencies and Repositories with AWS CodeArtifact
[Domain 3: Deployment – Task 1, Skills 3.1.1 Manage the dependencies of the code module (environment variables, configuration files) and 3.1.3 Use code repositories in deployment environments] Explains how a build gets its inputs: AWS CodeArtifact domains, repositories and upstream repositories for npm, pip and Maven packages, authorization tokens for package managers, source code repositories as the trigger and input for deployments, and keeping environment variables and configuration files out of the artifact so one build runs everywhere. - Level 39: Environment-Specific Configuration with AWS AppConfig
[Domain 3: Deployment – Task 1, Skill 3.1.5 Prepare application configurations for specific environments (for example, by using AWS AppConfig)] Teaches AWS AppConfig from first principles: applications, environments and configuration profiles, feature flags and freeform configuration, validators, deployment strategies with bake time and alarm-based rollback, and retrieving configuration from code through the AppConfig Agent or Lambda extension. - Level 40: AWS CloudFormation Template Fundamentals
[Domain 3: Deployment – Task 3, Skill 3.3.4 Implement and deploy infrastructure as code (IaC) templates (for example, AWS CloudFormation templates)] Introduces infrastructure as code with AWS CloudFormation: templates and stacks, the Parameters, Mappings, Conditions, Resources and Outputs sections, intrinsic functions such as Ref, Fn::GetAtt and Fn::Sub, pseudo parameters, and creating a stack from the CLI and reading its events when it fails. - Level 41: Testing Lambda Code with Test Events and SAM
[Domain 3: Deployment – Task 2: Test applications in development environments; Task 3: Automate deployment testing] You learn to test deployed and local code using JSON test events for Lambda, API Gateway and AWS SAM resources, including the event shapes that event-driven applications receive from SQS, SNS, EventBridge and S3. - Level 42: Integration Tests, Mock APIs and Development Endpoints
[Domain 3: Deployment – Task 2: Test applications in development environments] You learn to write integration tests against real development endpoints, and to replace external dependencies with mock APIs such as API Gateway mock integrations, so tests stay repeatable. - Level 43: API Gateway Stages, Stage Variables and Custom Domains
[Domain 3: Deployment – Task 3: Automate deployment testing; Task 4: Deploy code by using CI/CD services] You learn how API Gateway separates development, test and production using deployments, stages, stage variables and custom domain names, and how stage variables drive dynamic deployments into Lambda. - Level 44: Approved Versions: Aliases, Image Tags and Branches
[Domain 3: Deployment – Task 3: Automate deployment testing; Task 4: labels and branches for release management] You learn to build integration-test environments that pin approved versions using Lambda versions and aliases, container image tags and digests in ECR, AWS Amplify branches and AWS Copilot environments, and to use Amazon Q Developer to generate automated tests. - Level 45: Updating IaC Stacks Across Environments
[Domain 3: Deployment – Task 2: deploy application stack updates to existing environments; Task 3 and Task 4: implement, deploy and update IaC templates] You learn to update existing AWS SAM and CloudFormation stacks safely and to deploy one template to several staging environments using parameters, change sets and `samconfig.toml`. - Level 46: CodeBuild and the buildspec File
[Domain 3: Deployment – Task 4: Deploy code by using AWS CI/CD services] You learn how AWS CodeBuild turns a commit into tested artifacts, by reading and writing a `buildspec.yml` with its phases, environment variables, artifacts, reports and cache. - Level 47: CodeDeploy on EC2: appspec, Hooks and Rolling Deploys
[Domain 3: Deployment – Task 4: deployment strategies, rollbacks] You learn how AWS CodeDeploy deploys to the EC2/on-premises compute platform with an `appspec.yml`, lifecycle event hooks, in-place and blue/green deployment types, and deployment configurations that control rolling behaviour. - Level 48: Canary, Linear and Blue/Green for Lambda and ECS
[Domain 3: Deployment – Task 4: configure deployment strategies (blue/green, canary, rolling) and perform rollbacks] You learn how CodeDeploy shifts traffic for Lambda aliases and Amazon ECS services using canary, linear and all-at-once configurations, and how AWS SAM sets this up with `AutoPublishAlias` and `DeploymentPreference`. - Level 49: CodePipeline, Beanstalk Policies and Amplify Releases
[Domain 3: Deployment – Task 4: commit code to invoke build, test and deployment actions; orchestrated workflows; manage application environments] You learn to orchestrate source, build, test, approval and deploy stages in AWS CodePipeline, and to manage environments with Elastic Beanstalk deployment policies and AWS Amplify branch deployments. - Level 50: Logging, Monitoring, Observability and Structured Logs
[Domain 4: Troubleshooting and Optimization – Task 2: Instrument code for observability] You learn the differences between logging, monitoring and observability, and how to implement a logging strategy with structured JSON logs in CloudWatch Logs that record application behaviour, state and user actions without leaking sensitive data. - Level 51: Querying Logs with CloudWatch Logs Insights
[Domain 4: Troubleshooting and Optimization – Task 1: query logs to find relevant data; Task 3: use application logs to identify performance bottlenecks] You learn to find the relevant data quickly using CloudWatch Logs Insights queries, filter patterns and metric filters, and to read Lambda REPORT lines for duration, memory and cold-start evidence. - Level 52: Custom Metrics and Embedded Metric Format
[Domain 4: Troubleshooting and Optimization – Task 1: implement custom metrics (CloudWatch embedded metric format); Task 2: implement code that emits custom metrics] You learn to publish application metrics from code using `PutMetricData` and the CloudWatch embedded metric format (EMF), and when each one fits. - Level 53: Alarms, Dashboards and Notification Alerts
[Domain 4: Troubleshooting and Optimization – Task 1: review application health by using dashboards and insights; Task 2: implement notification alerts for specific actions] You learn to turn metrics into action with CloudWatch alarms, composite alarms and dashboards, and to send notifications about quota limits, errors and deployment completions through Amazon SNS and EventBridge rules. - Level 54: Tracing with AWS X-Ray: Segments and Annotations
[Domain 4: Troubleshooting and Optimization – Task 2: implement tracing by using AWS services and tools; add annotations for tracing services] You learn how AWS X-Ray follows a request across services using segments, subsegments, sampling and the trace map, and how to instrument code with annotations and metadata, including the OpenTelemetry-based route AWS now recommends. - Level 55: Root Cause Analysis: Errors, Throttles and CloudTrail
[Domain 4: Troubleshooting and Optimization – Task 1: debug code to identify defects; interpret application metrics, logs and traces; debug service integration issues] You learn a repeatable method for root cause analysis using HTTP and SDK error codes, service metrics, traces and AWS CloudTrail to separate code defects from permission, throttling and integration faults. - Level 56: Troubleshooting Deployment Failures from Service Logs
[Domain 4: Troubleshooting and Optimization – Task 1: troubleshoot deployment failures by using service output logs] You learn where each deployment service reports failure (CloudFormation stack events, CodeBuild build logs, CodeDeploy agent and lifecycle event logs, Elastic Beanstalk events, ECS service events and stopped-task reasons) and how to read them to find the cause. - Level 57: Health Checks, Readiness Probes and Network Behaviour
[Domain 4: Troubleshooting and Optimization – Task 2: configure application health checks and readiness probes] You learn how Elastic Load Balancing target group health checks, Route 53 health checks, ECS container health checks and Amazon EKS liveness and readiness probes decide where traffic goes, and how VPC security groups, network ACLs and subnets cause false failures. - Level 58: Concurrency, Memory and Profiling for Performance
[Domain 4: Troubleshooting and Optimization – Task 3: define concurrency; profile application performance; determine minimum memory and compute power; optimize application resource usage] You learn how Lambda concurrency really works (account limits, reserved and provisioned concurrency) and how to right-size memory and compute by profiling, not guessing. - Level 59: Caching Strategies and Subscription Filter Policies
[Domain 4: Troubleshooting and Optimization – Task 3: cache content based on request headers; implement application-level caching; use subscription filter policies to optimize messaging; analyze application performance issues] You learn to remove unnecessary work with CloudFront cache policies keyed on headers, API Gateway stage caching, ElastiCache lazy-loading and write-through patterns, and Amazon SNS subscription filter policies. - Level 60: Infrastructure as Code with the AWS CDK
[Domain 3: Deployment] Teaches the AWS Cloud Development Kit (AWS CDK), the in-scope service no earlier level names: infrastructure defined in a programming language, synthesised to AWS CloudFormation, and how it sits beside AWS SAM and hand-written templates. - Level 61: Timed Mock Exam: 65 Questions in 130 Minutes Timed mock
[All four domains] The timed mock exam of 65 original multiple-choice and multiple-response scenario questions tests Development with AWS Services, Security, Deployment, and Troubleshooting and Optimization in proportion to their 32/26/24/18 weightings, with a 72% pass mark and every distractor explained.
Access
The first 2 levels are free with a free account. Every level, the podcast edition and the AI tutor come with All Access at £4.99/month or any Creator plan — see pricing.