AWS Certified Developer – Associate (DVA-C02) Study Guide: Domains and Study Plan
An AWS DVA-C02 guide covering the four exam domains, application development, deployment, and a practical study plan.
The AWS Certified Developer – Associate (DVA-C02) exam tests how to develop, test, deploy, and debug applications on AWS. It focuses on AWS APIs and SDKs, application security, CI/CD, and troubleshooting—not deep architecture design or systems operations.
Objectives can change, so use the latest AWS DVA-C02 exam guide. The guide also lists emerging AI-assisted development topics as pretest questions; AWS states these do not affect your score.
Who is this exam for? What background helps?
The exam suits application and backend developers and people who want to learn AWS development, deployment, and debugging. Familiarity with at least one programming language, HTTP/APIs, and the application lifecycle helps. AWS recommends experience developing and maintaining applications with AWS services; this is candidate guidance, not a registration requirement.
DVA-C02 focuses on implementation. SAA-C03 focuses on architecture choices, while SOA-C03 focuses on day-to-day operations.
Exam domains and weights
| Domain | Official name | Main focus | Weight |
|---|---|---|---|
| 1 | Development with AWS Services | Building and optimizing apps with AWS services | 32% |
| 2 | Security | Credentials, access control, and data protection | 26% |
| 3 | Deployment | Application artifacts, testing, and continuous deployment | 24% |
| 4 | Troubleshooting and Optimization | Debugging, performance, and resource optimization | 18% |
Domain 1 has the largest weight, but security and deployment also make up a substantial part of the exam. Weights are percentages of scored content; use the official guide for detailed skills.
How to study each domain
Domain 1: Development with AWS Services
Learn to build application logic with AWS services, APIs, the CLI, or SDKs, including compute, data stores, events, and messaging. Understand the boundary between synchronous requests and asynchronous messages, and plan for state and failed retries.
Common mix-up: treating event source mappings, retries, and idempotency as the same mechanism. Draw the flow—trigger, handler, persistence, notification—and decide how duplicate events are handled.
Domain 2: Security
Study how applications obtain temporary credentials, how to apply least privilege, and how to protect data and manage keys. Understand IAM roles, Secrets Manager, parameter storage, and KMS in context.
Common mix-up: placing long-term access keys in code, or confusing trust policies with permission policies. Trace where credentials come from, then identify which actions they allow on which resources.
Domain 3: Deployment
Learn how to package applications, test them in development environments, automate deployment tests, and release code with CI/CD services. Understand environment configuration, secret injection, release strategies, and rollback verification.
Common mix-up: memorizing blue/green or canary deployment names without considering failure and data compatibility. Include validation signals and rollback conditions in your release plan.
Domain 4: Troubleshooting and Optimization
Use logs, metrics, and traces to locate application issues. Understand common performance, concurrency, and cost trade-offs.
Common mix-up: checking only application code while overlooking permissions, dependencies, quotas, or networking. Verify code, identity, dependencies, and capacity separately; establish a baseline before optimizing.
Suggested study order
- IAM roles, temporary credentials, and data protection.
- Application paths using Lambda, API Gateway, DynamoDB, and similar services.
- Asynchronous integration with SQS/SNS, retries, and idempotency.
- CI/CD, deployment validation, and rollback.
- Logs, tracing, and performance optimization.
Check your readiness with three questions
- In an API-to-queue workflow, where are retries and idempotency handled?
- How does an app get temporary credentials, and how are permissions limited to required resources?
- If a release fails, what signal triggers rollback, and how do you verify recovery?
A three-step preparation plan
- Read the official guide. Check your gaps against tasks in all four domains.
- Map an application flow. Start with a request or event and mark identity, service calls, storage, deployment, and monitoring.
- Practice and review. Group misses by domain; for recurring errors, revisit the official skill and AWS documentation.
Start practicing
When you are ready, use exam code DVA-C02 to practice by domain, then review the matching exam objectives.