Courseiva
Data Operations and Support →mediumMultiple Choice

DEA-C01 Data Operations and Support Practice Question

Network Topology
$ aws logs describe-log-groupslog-group-name-prefix "/aws/lambda/data-processor"Refer to the exhibit.```"logGroups": ["logGroupName": "/aws/lambda/data-processor","creationTime": 1617000000000,"metricFilterCount": 0,"arn": "arn:aws:logs:us-east-1:123456789012:log-group:/aws/lambda/data-processor:*","storedBytes": 0,"retentionInDays": 7

Refer to the exhibit. A data engineer is troubleshooting an AWS Lambda function that processes data from Amazon S3. The function is triggered by S3 events, but no logs appear in CloudWatch Logs. The engineer runs the AWS CLI command shown. What is the MOST likely reason for the missing logs?

⚠ Common exam trap

DEA-C01 often tests the misconception that Lambda automatically has permissions to write logs, but the execution role must explicitly allow it; candidates may overlook this and choose other options like log retention or invocation issues.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Lambda execution role does not have permissions to create log groups and write logs.

The most likely reason for missing CloudWatch Logs is that the Lambda execution role lacks the necessary permissions to create log groups and write log streams. When a Lambda function is invoked, it attempts to create a log group named /aws/lambda/<function-name> and a log stream, then write logs. If the execution role does not include actions like logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents, the function cannot write any logs, resulting in no log entries. This is a common misconfiguration, especially when roles are custom-created without the default AWSLambdaBasicExecutionRole policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The Lambda execution role does not have permissions to create log groups and write logs.

    Why this is correct

    Without `logs:CreateLogGroup`, `logs:CreateLogStream` and `logs:PutLogEvents` in the execution role, Lambda cannot create the function's log group or stream, so invocations produce no CloudWatch output at all. This directly satisfies the stem's missing-logs constraint, since the trigger itself is firing normally.

  • ✗

    The Lambda function is configured to log to a different log group.

    Why it's wrong here

    Lambda writes to the log group /aws/lambda/<function-name> by default; a different destination requires explicit configuration, which the exhibit does not show. It is tempting because log routing can be customised, and would be correct if the function's execution role or logging configuration pointed elsewhere.

  • ✗

    The Lambda function is not being invoked by S3 events.

    Why it's wrong here

    Missing logs do not establish that S3 is failing to invoke the function; an invocation error would surface as throttling or permission failures, and the exhibit shows the configuration being inspected instead. It is tempting because no logs suggests nothing ran, and would be correct if metrics showed zero invocations.

  • ✗

    The log retention policy is set to 7 days, causing logs to expire immediately.

    Why it's wrong here

    A 7-day retention policy deletes logs after seven days, not instantly, so it cannot explain logs absent from the moment of invocation. It is tempting because retention settings do govern log lifecycle, and would be the culprit if logs had appeared and later vanished.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.