DEA-C01 Data Operations and Support Practice Question
Network Topology
Refer to the exhibit. A data engineer is troubleshooting an AWS Lambda function that processes data from Amazon S3. The function is triggered by S3 events, but no logs appear in CloudWatch Logs. The engineer runs the AWS CLI command shown. What is the MOST likely reason for the missing logs?
⚠ Common exam trap
DEA-C01 often tests the misconception that Lambda automatically has permissions to write logs, but the execution role must explicitly allow it; candidates may overlook this and choose other options like log retention or invocation issues.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Lambda execution role does not have permissions to create log groups and write logs.
The most likely reason for missing CloudWatch Logs is that the Lambda execution role lacks the necessary permissions to create log groups and write log streams. When a Lambda function is invoked, it attempts to create a log group named /aws/lambda/<function-name> and a log stream, then write logs. If the execution role does not include actions like logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents, the function cannot write any logs, resulting in no log entries. This is a common misconfiguration, especially when roles are custom-created without the default AWSLambdaBasicExecutionRole policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The Lambda execution role does not have permissions to create log groups and write logs.
Why this is correct
Without `logs:CreateLogGroup`, `logs:CreateLogStream` and `logs:PutLogEvents` in the execution role, Lambda cannot create the function's log group or stream, so invocations produce no CloudWatch output at all. This directly satisfies the stem's missing-logs constraint, since the trigger itself is firing normally.
- ✗
The Lambda function is configured to log to a different log group.
Why it's wrong here
Lambda writes to the log group /aws/lambda/<function-name> by default; a different destination requires explicit configuration, which the exhibit does not show. It is tempting because log routing can be customised, and would be correct if the function's execution role or logging configuration pointed elsewhere.
- ✗
The Lambda function is not being invoked by S3 events.
Why it's wrong here
Missing logs do not establish that S3 is failing to invoke the function; an invocation error would surface as throttling or permission failures, and the exhibit shows the configuration being inspected instead. It is tempting because no logs suggests nothing ran, and would be correct if metrics showed zero invocations.
- ✗
The log retention policy is set to 7 days, causing logs to expire immediately.
Why it's wrong here
A 7-day retention policy deletes logs after seven days, not instantly, so it cannot explain logs absent from the moment of invocation. It is tempting because retention settings do govern log lifecycle, and would be the culprit if logs had appeared and later vanished.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.