Development with AWS Services
A developer wants a Lambda function to reuse a database connection across invocations to reduce latency. Where should the connection be created?
- AInside the handler on every invocation
- BIn an environment variable
- CIn a separate Lambda layer that cannot run code
- DOutside the handler, in the initialization code that runs once per execution environmentCorrect
Why: Code outside the handler runs once when the execution environment initializes and is reused across warm invocations, so creating the connection there avoids re-establishing it on every call. Creating it inside the handler would open a new connection each invocation. Layers package dependencies but do not execute standalone, and environment variables hold configuration, not live connections.
Security
An application needs to let thousands of end users sign in with email or their Google account and then call AWS APIs with scoped permissions. Which combination is appropriate?
- ACreate one IAM user per end user
- BUse an IAM role shared by all users with wildcard permissions
- CEmbed root account credentials in the app
- DAmazon Cognito user pools for sign-in plus identity pools to obtain temporary IAM credentialsCorrect
Why: Cognito user pools handle sign-up and sign-in (including social federation) and issue tokens; identity pools exchange those tokens for temporary, scoped IAM credentials. Creating an IAM user per person does not scale, a shared wildcard role violates least privilege, and root credentials must never be embedded.