GregLab | Exam Prep

Security, Identity, and Compliance

Core

AWS Identity and Access Management (IAM)

Service for controlling authentication and authorization of AWS principals and requests.

Key points

  • Roles provide temporary workload and delegated identity without embedded long-term credentials.
  • Identity policies control principal permissions; role trust policies control role assumption.
  • Least privilege scopes actions, resources, and conditions to the application need.

Best-known use cases

  • Authorize a Lambda or container workload to call AWS services.
  • Define and troubleshoot role assumption and cross-service access.

What candidates often confuse it with

  • IAM/STS governs AWS principal sessions; Cognito governs application-user identity flows.
  • Trust answers who may assume a role; permissions answer what the session may do.

Key takeaway

Use scoped roles and distinguish principal permissions from role trust and resource authorization.

Related services

  • AWS Security Token Service (AWS STS)
  • Amazon Cognito
  • AWS Key Management Service (AWS KMS)

Relevant exam tasks

  • D2.1 — Implement authentication and/or authorization for applications and AWS services
  • 2.1.1 — Use an identity provider to implement federated access (for example, Amazon Cognito, IAM)
  • 2.1.3 — Configure programmatic access to AWS
  • 2.1.4 — Make authenticated calls to AWS services
  • 2.1.5 — Assume an IAM role
  • 2.1.6 — Define permissions for IAM principals
  • 2.1.8 — Handle cross-service authentication in microservice architectures

Learn more

Free AWS Certified Developer - Associate prep

Build focused DVA-C02 quizzes from skill areas, topics, and product references.

Practice with exam-style multiple-choice and multiple-response questions, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Read Topics Build a quiz

Exam Weights

Exam snapshot

DVA-C02 at a glance

Category
Associate
Duration
130 minutes
Questions
65 total; 50 scored and 15 unidentified unscored
Formats
Multiple choice and multiple response
Scoring
100–1,000 scaled score; 720 minimum passing score

Quiz builder

Choose your practice set

Mode

Exam fidelity: AWS documents 65 questions in 130 minutes: 50 scored and 15 unidentified unscored, using multiple-choice and multiple-response formats. This site's practice accuracy and readiness do not reproduce AWS's 100–1,000 scaled scoring or identify unscored items. Difficulty labels describe this site's Associate-level scenario complexity, not an AWS-published question rating.

Reference

DVA-C02 topics and reference map

Study links

DVA-C02 resources