Courseiva

DVA-C02 Development with AWS Services Practice Question

A developer is building a serverless application using AWS Lambda. The function needs to access a DynamoDB table and write logs to Amazon CloudWatch. What is the minimum set of IAM permissions the Lambda execution role must have?

⚠ Common exam trap

The trap here is that candidates often forget that Lambda requires both `logs:CreateLogGroup` and `logs:CreateLogStream` (not just `logs:PutLogEvents`) to set up CloudWatch logging, or they assume `dynamodb:GetItem` is needed for writing, leading them to choose Option D.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

dynamodb:PutItem, logs:CreateLogGroup, logs:CreateLogStream, logs:PutLogEvents

The Lambda execution role must include `dynamodb:PutItem` to write to the DynamoDB table, and the three `logs:` permissions (`CreateLogGroup`, `CreateLogStream`, `PutLogEvents`) are required for Lambda to create log groups/streams and send log events to CloudWatch Logs. This is the minimum set that satisfies both requirements without granting unnecessary privileges.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    dynamodb:PutItem, logs:CreateLogGroup, logs:CreateLogStream, logs:PutLogEvents

    Why this is correct

    This option provides the precise set of permissions required for a serverless application, such as an AWS Lambda function, to operate effectively. `dynamodb:PutItem` enables the function to write data to a DynamoDB table, fulfilling its primary data interaction requirement. Concurrently, `logs:CreateLogGroup`, `logs:CreateLogStream`, and `logs:PutLogEvents` grant the necessary capabilities for the Lambda function to establish its dedicated log group and stream, then continuously publish its execution logs to CloudWatch, ensuring comprehensive operational visibility. This adheres to the principle of least privilege by granting only essential actions.

  • ✗

    logs:CreateLogGroup, logs:CreateLogStream, logs:PutLogEvents

    Why it's wrong here

    While this option correctly includes all the necessary permissions for a Lambda function to create its log group and stream, and then publish log events to CloudWatch Logs, it critically omits any permissions for interacting with DynamoDB. If the serverless application's core functionality involves storing or retrieving data from a DynamoDB table, the absence of actions like `dynamodb:PutItem` will result in access denied errors, preventing the application from performing its intended data persistence operations.

  • ✗

    dynamodb:*, logs:PutLogEvents

    Why it's wrong here

    This set of permissions is problematic due to two distinct issues. Firstly, `dynamodb:*` grants overly broad access to all DynamoDB actions, violating the principle of least privilege if the application only requires `PutItem` or a subset of operations, thereby introducing unnecessary security risks. Secondly, `logs:PutLogEvents` is insufficient for comprehensive logging, as it lacks the crucial `logs:CreateLogGroup` and `logs:CreateLogStream` permissions, which are essential for a Lambda function to initialize its logging infrastructure in CloudWatch.

  • ✗

    dynamodb:GetItem, dynamodb:PutItem, logs:PutLogEvents

    Why it's wrong here

    This option is flawed because it includes an unnecessary `dynamodb:GetItem` permission if the application's sole purpose is to write data, thereby granting more access than required and failing to adhere to the principle of least privilege. Furthermore, similar to other incorrect logging configurations, it only provides `logs:PutLogEvents`, critically missing the `logs:CreateLogGroup` and `logs:CreateLogStream` permissions. Without these, the Lambda function will be unable to set up its logging environment in CloudWatch, leading to failed log initialization.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.