certslothcertsloth
SAP-C02/Topic 18

AWS / Professional

Serverless solution architectures

6 min read5 recall promptsReviewed 2026-10-10

Memory hook: Authenticate the caller, authorize the operation, keep durable state outside functions, and cache only responses safe to share.

Must remember

A mobile records application needs more than a login screen

  • A common request path is client → API Gateway → Lambda → DynamoDB. Cognito can provide sign-in and tokens; an authorizer validates identity at the API boundary.
  • Authentication identifies the caller. Authorization decides whether that caller can perform this operation on this record. Derive the owner/tenant from validated identity rather than trusting an arbitrary user ID in the request body.
  • Model DynamoDB partition/sort keys around the application's access patterns, such as “this user's records in date order.” Avoid reading everyone's data and filtering it in the client.
  • User pools supply sign-in tokens. Identity pools supply temporary AWS credentials when clients need direct permitted AWS access. Do not ship permanent AWS access keys inside a mobile or browser application.
  • Large uploads can go directly to S3 using a narrowly authorized pre-signed upload or temporary role credentials, while the API coordinates metadata and authorization. This avoids needlessly proxying all file bytes through application compute.
  • API request throttling, Lambda concurrency limits and database capacity form one system: buffering or explicit backpressure can be more useful than increasing every quota. See serverless service choices. AWS serverless architecture patterns

A publishing website has static and dynamic paths

  • Store immutable HTML/assets/media in S3 and serve them through CloudFront. Use a private S3 REST origin with OAC where the origin must be inaccessible directly.
  • Keep authenticated comments, edits and personal data behind an authorized dynamic API. A public homepage and a private account page should not inherit the same caching assumptions.
  • Choose cache keys around the representation being served. Missing relevant identity/authorization variation can expose private content; unnecessary cookies/headers can destroy useful cache reuse.
  • Prefer long-lived caching for content-addressed or versioned assets. A short-lived manifest can identify the current release while older immutable assets remain cacheable.
  • Separate viewer-to-CloudFront, CloudFront-to-origin, API-to-Lambda and Lambda-to-data permissions. A valid login does not automatically grant every downstream permission. API Gateway invocation permissions

Decouple microservices deliberately

  • Let each service own a clear interface and data boundary. Sharing one writable database schema across every service can make deployment and failure isolation harder.
  • Synchronous APIs fit operations that require an immediate answer, but the caller inherits downstream latency and failures. Use timeouts, limited retries and appropriate circuit-breaking/backpressure behavior.
  • Queues/events fit deferred work. SQS buffers work; SNS/EventBridge can distribute events; independent queues let consumers recover at different rates. This introduces eventual completion rather than a synchronous transaction.
  • Idempotency protects retries: identify the business operation and atomically recognize work already committed. A generated event ID alone is not enough if repeated requests get unrelated IDs.
  • For multi-step work, Step Functions makes state, retry/catch paths and compensation visible. Compensating business actions are not equivalent to rolling back a distributed database transaction.
  • Use metrics, structured logs and AWS X-Ray traces where supported to locate latency across service boundaries. A trace explains the request path; it does not authorize that request. See messaging patterns.

Deliver software and test real clients

  • Software distribution: place versioned binaries in S3 and cache them at CloudFront edges. Calling Lambda for every identical download adds work without creating a CDN cache.
  • Signed URLs restrict particular downloadable resources; signed cookies can authorize a collection without rewriting every asset URL. Keep OAC or other origin restrictions so clients cannot bypass the viewer control.
  • CDN caches improve delivery, not durable recovery. Use replication and an appropriate origin recovery/failover design if regional resilience is required; measure RPO/RTO separately. Signed viewer access
  • AWS Device Farm tests mobile/web applications on hosted real devices and browser environments. It addresses device/browser compatibility and user-interface behavior, not API hosting, application distribution or infrastructure provisioning.
  • A backend unit test can pass while a particular mobile browser fails sign-in, CORS handling or rendering. Device testing and API/integration tests therefore complement each other; use controlled test accounts and datasets. Device Farm purpose

Choose under exam pressure

Requirement in the question Best direction
Authenticated per-user records Authorizer plus item-level authorization
Static global content with few origin reads S3 and CloudFront
Direct large client uploads Authorized direct S3 upload pattern
Slow background processing Queue and asynchronous consumer
Multi-step retry/compensation workflow Step Functions
Restricted collection of downloadable files Signed cookies
Client compatibility across physical devices Device Farm

Traps

  • A valid JWT does not grant permission to another user's record.
  • Broadly caching personalized API responses can leak data even when the origin is private.
  • “Serverless” does not remove quotas, idle provisioned features, request charges or service failure boundaries.
  • A directly invocable Lambda function can still fail when API Gateway lacks its own invoke permission.

Active recall

1. An API validates login tokens but accepts any owner ID supplied in the request. What security requirement is still missing?

Record-level authorization. Use the validated principal/tenant context to constrain access rather than trusting the client's claimed owner. Authentication alone does not prevent cross-user access.

2. Users upload large files and Lambda merely relays the bytes. What architectural change reduces unnecessary compute?

Authorize a direct upload to S3 and let the API manage metadata and access decisions. The file path then avoids unnecessary application payload handling while retaining scoped authorization.

3. A report takes several minutes, but clients need a quick acknowledgement. Should the HTTP request wait for all processing?

Usually queue the work and return an accepted/job reference, then expose completion status or a notification. This decouples user latency from processing duration and permits controlled retries.

4. A paid download works through CloudFront but also through a public S3 URL. Are signed viewer URLs sufficient?

No. The public origin bypasses the viewer restriction. Restrict direct origin access, for example with a private REST origin and OAC, as well as authenticating the viewer path.

5. Backend integration tests pass, but sign-in fails on particular phone/browser combinations. Which additional service fits?

Device Farm can exercise application behavior across hosted devices and browser environments. It complements backend tests; changing the API's compute platform alone does not diagnose client compatibility.

Terraform anchor: Derive route keys, Lambda invoke-policy conditions and client outputs from one contract so an API path change updates every dependent boundary.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.