
AWSCertified Developer - Associate
Domain 2Objective 2
Task 2: Implement Encryption by Using AWS Services DVA-C02 Practice Questions (Page 3)
Part of the Content Domain 2: Security domain, which accounts for 26% of the DVA-C02 exam. AWS does not publish an official question count, but from its 130-minute exam (~50–85 total, ~13–22 in this domain), expect 4–7 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)
22questions here
5free pages
7concepts
26%of the exam
Questions 11–15
- 11
A developer is building an application that must encrypt sensitive data before it is sent to an API. The API will store the encrypted data without ever having access to the plaintext. Which encryption approach should the developer use?
Select an answer first - 12
A developer has encrypted data using an AWS KMS key and needs to decrypt it programmatically. Which AWS KMS API operation should the developer use?
Select an answer first - 13
Which statement correctly describes a difference between client-side and server-side encryption?
Select an answer first - 14
Which AWS KMS feature is used to allow an IAM principal in another AWS account to use a KMS key?
Select an answer first - 15
A company operates a private API that is only accessible within its VPC. The API must use TLS, but the company does not want to use publicly trusted certificates. Which approach should the developer take?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “DVA-C02” is a trademark of its owner, used for identification only.