DVA-C02 Security Practice Question
Network Topology
A developer created the following IAM role for a Lambda function:
```json
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {"Service": "lambda.amazonaws.com"},
"Action": "sts:AssumeRole"
}
]
}```
The function needs to write logs to CloudWatch Logs. What is missing?
⚠ Common exam trap
The trap here is that candidates may overlook the specific CloudWatch Logs permissions required for Lambda logging and instead focus on trust policy or naming issues, but the missing element is the permissions policy granting the necessary logging actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The role needs a permissions policy that grants logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents.
The role shown includes a trust policy that allows Lambda to assume the role but does not include an attached permissions policy for CloudWatch Logs. To write logs to CloudWatch Logs, the Lambda function must be granted logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents through a permissions policy attached to the role.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The role needs a permissions policy that grants logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents.
Why this is correct
Lambda functions automatically publish logs to Amazon CloudWatch Logs. For this logging mechanism to function correctly, the IAM execution role assigned to the Lambda function must possess a permissions policy granting specific actions: logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents. Without these essential permissions, the Lambda function will be unable to create its dedicated log resources or write any operational data and errors to CloudWatch, severely impacting monitoring and debugging capabilities.
- ✗
The trust policy is incorrect; it should allow ec2.amazonaws.com.
Why it's wrong here
An IAM role's trust policy dictates which entities are authorized to assume that role. For an AWS Lambda function, the correct service principal that needs permission to assume the role is lambda.amazonaws.com. Specifying ec2.amazonaws.com in the trust policy is incorrect for a Lambda function, as that principal is exclusively used for Amazon EC2 instances to assume roles, not for serverless functions.
- ✗
The role name is invalid.
Why it's wrong here
AWS IAM role names adhere to specific naming conventions, typically allowing alphanumeric characters along with common symbols like hyphens, underscores, periods, and at signs, with a length between 1 and 64 characters. Unless the provided role name contains invalid characters or exceeds the length limits, it is generally considered valid. Therefore, stating that the role name is invalid without specific context of a violation is incorrect.
- ✗
The trust policy should not allow Lambda to assume the role.
Why it's wrong here
It is absolutely essential for the trust policy of an IAM role assigned to a Lambda function to allow lambda.amazonaws.com to assume the role. This sts:AssumeRole permission is fundamental, as it enables the Lambda service to temporarily take on the identity and permissions defined by the role. Without this explicit authorization in the trust policy, the Lambda function would be unable to execute with any associated permissions, rendering it incapable of interacting with other AWS services.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.