AWS practice questions: 900 questions with full explanations
- Questions on the exam
- about 65 — vendor indicates, no fixed count published
- Time allowed
- 130 minutes format →
900 practice questions for AWS Certified Data Engineer – Associate, grouped by exam domain. Every question below shows all four options, which one is correct, and why each of the other three is not — the wrong answers are where most candidates lose marks.
Not sure where you stand? Take the free 5-min AWS readiness check →
AWS certification: requirements, cost and exam format → · AWS exam format → ·
Questions by domain
- 1: Data Ingestion and Transformation — 306 questions →
- 2: Data Store Management — 234 questions →
- 3: Data Operations and Support — 198 questions →
- 4: Data Security and Governance — 162 questions →
Sample questions
Split each device across subkeys and resequence: Which change best addresses the problem?
Exhibit: partition key = deviceId; shard capacity = 1 MB/s writes.
- Add consumers that read the hot shard before accepting more device records.Consumer coordination does not redistribute writes or increase the hot shard's capacity.
- Split each device across subkeys and resequence by its device sequence value. ✓Subkeys distribute one hot device across shards, while downstream resequencing preserves device order without requiring global ordering.
- Use sequence numbers as partition keys for all records.Kinesis assigns sequence numbers after ingestion, so producers cannot use them to route incoming records.
- Increase PutRecords batch size until the hot shard accepts the device.PutRecords improves request efficiency but does not bypass a shard's write-throughput limit.
All 306 1: Data Ingestion and Transformation questions →
Amazon Athena querying the S3 data lake: Which service is the best primary query store?
- Amazon RDS for PostgreSQL containing every historical transaction row.RDS adds relational administration and storage loading for a workload already suited to querying S3 files.
- Amazon DynamoDB with a partition key for transaction date.DynamoDB suits known-key operational access, not broad ad hoc joins across years of immutable files.
- Amazon Athena querying the S3 data lake. ✓Athena queries Parquet files in S3 without requiring a persistent warehouse for occasional analytical SQL workloads.
- Amazon Kinesis Data Streams retaining the transaction files for analyst queries.Kinesis provides streaming ingestion and retention, not a general-purpose SQL store for historical file analytics.
All 234 2: Data Store Management questions →
Use Step Functions: Which design best meets the requirement?
- Run a crawler before a scheduled ETL job.Crawler completion and ETL completion are separate operations, and scheduling does not guarantee the required validation dependency.
- Schedule validation and loading together.Simultaneous scheduled starts do not ensure validation succeeds before loading begins.
- Trigger the load directly from S3 and validate afterward.Direct loading bypasses the required validation gate and can publish invalid data.
- Use Step Functions. ✓A Step Functions workflow can start from the object event, validate the file, branch on the result, and prevent loading after failure.
All 198 3: Data Operations and Support questions →
Allow TCP 5432 inbound on DbSG from AppSG: Which update should restore access?
- Allow TCP 5432 inbound on DbSG from 0.0.0.0/0.This permits database access from every IPv4 source and violates the stated restriction against broad access.
- Allow TCP 5432 inbound on AppSG from DbSG.Inbound rules on the client group do not authorize the database’s inbound connection request.
- Attach the database security group to the application instances.Sharing a security group does not replace the required inbound rule on the database security group.
- Allow TCP 5432 inbound on DbSG from AppSG. ✓Referencing the application security group permits database traffic from current application members without broad subnet-based access.
All 162 4: Data Security and Governance questions →
Configure an AWS Glue job to read the S3 objects: Which option best fits?
- Create a Kinesis data stream and publish each CSV line as a separate streaming record.Kinesis could transport records, but it adds unnecessary streaming complexity to complete hourly batch files.
- Use an Amazon MSK consumer group to poll the S3 bucket for completed files.MSK consumers process Kafka records; they do not natively poll S3 as a batch-file ingestion mechanism.
- Configure DynamoDB Streams to discover newly created S3 objects and process their contents.DynamoDB Streams reports DynamoDB item changes and does not provide notifications for S3 object creation.
- Configure an AWS Glue job to read the S3 objects, transform rows, and write Parquet. ✓AWS Glue jobs provide managed batch processing for S3 files and can transform records into analytics-friendly output formats.
All 306 1: Data Ingestion and Transformation questions →
Use DynamoDB with tracking number as the partition key: Which storage configuration is most appropriate?
- Use Amazon Redshift with tracking number as a distribution key.Redshift targets analytical workloads and is unsuitable as the primary low-latency operational store for individual updates.
- Use Amazon S3 objects named with tracking numbers and scan prefixes for status.S3 object access lacks the convenient item update and indexed lookup behavior required by the application.
- Use Amazon Athena over JSON files partitioned by tracking number.Athena is designed for analytical queries and introduces unnecessary query execution overhead for frequent point operations.
- Use DynamoDB with tracking number as the partition key. ✓DynamoDB provides scalable key-based reads and updates when tracking number identifies each parcel item.
All 234 2: Data Store Management questions →
Inspect DAG dependencies and scheduler logs: Which investigation is most appropriate first?
- Inspect DAG dependencies and scheduler logs. ✓A pre-task failure commonly indicates dependency, parsing, or scheduling issues, so DAG state and scheduler evidence should be checked first.
- Increase retries without reviewing logs or dependencies.Retries do not correct invalid DAG dependencies or parsing problems and can obscure the original cause.
- Reset the integration's Glue bookmarks.Glue bookmarks track source-processing state and do not diagnose an MWAA DAG that fails before task execution.
- Restart downstream applications.Downstream restarts do not explain a DAG failure before task execution and may disrupt healthy systems.
All 198 3: Data Operations and Support questions →
Store it in Secrets Manager with rotation enabled: Which solution best satisfies these requirements?
- Create an IAM user and embed its access keys in the pipeline configuration.IAM access keys are static AWS credentials and do not manage the database password.
- Place the password in an S3 object and grant the pipeline read access.S3 stores the value but does not by itself rotate database credentials or coordinate refreshed connections.
- Store it in Secrets Manager with rotation enabled. ✓Secrets Manager stores the password centrally, supports configured rotation, and allows runtime retrieval of the current value.
- Store the password in an encrypted configuration file deployed with the pipeline.Encryption protects the file but does not provide managed rotation or eliminate the need to distribute decryption material.
All 162 4: Data Security and Governance questions →
AWS exam: the facts
How many questions are on the AWS exam?
Around 65. The vendor does not publish a fixed count for AWS, so this is the figure it indicates rather than a guaranteed number.
How long is the AWS exam?
130 minutes. Across 65 questions that is about 120 seconds per question.
What topics does the AWS exam cover?
4 domains: 1: Data Ingestion and Transformation, 2: Data Store Management, 3: Data Operations and Support, 4: Data Security and Governance. Weights: 1: Data Ingestion and Transformation 34%, 2: Data Store Management 26%, 3: Data Operations and Support 22%, 4: Data Security and Governance 18%.
How many AWS practice questions does Certsqill have?
900, spread across 4 exam domains. Every one shows all options, which is correct, and why each of the others is not.
Would you pass AWS today?
Five minutes, and you get a score per domain — not one number, but which section to open tonight.
Test your AWS readiness — free