Courseiva
Security →hardMultiple Choice

DVA-C02 Security Practice Question

A developer is building a serverless order-processing application. An AWS Lambda function must read records from an Amazon DynamoDB table and write audit entries to an Amazon SQS queue. The developer creates the Lambda execution role and attaches a managed policy that grants dynamodb:GetItem, dynamodb:PutItem, sqs:SendMessage, and logs:CreateLogGroup permissions on the specific resources. After deployment, the Lambda function successfully reads and writes to DynamoDB, but every attempt to send a message to the SQS queue fails with an AccessDenied error. The developer confirms the SQS queue URL in the code is correct and the queue exists in the same AWS Region. Which action will resolve this issue with the LEAST privilege?

⚠ Common exam trap

The trap here is assuming that any AccessDenied error means the action is missing from the policy, when in fact the action is present but scoped to the wrong resource ARN.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Update the Lambda execution role's identity-based policy to use the SQS queue's ARN as the Resource for the sqs:SendMessage statement.

The Lambda execution role already includes the sqs:SendMessage action, so the denial is caused by the Resource element not matching the target queue's ARN. AWS evaluates identity-based policies by matching the requested resource against the Resource element; a mismatch results in an implicit deny. Correcting the Resource to the queue's ARN grants exactly the needed permission on the intended queue, which resolves the error while honoring least privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add a resource-based policy to the SQS queue that allows the Lambda execution role to call sqs:SendMessage.

    Why it's wrong here

    SQS queue policies are resource-based policies that grant access to principals, and they can allow a role to send messages. However, in this scenario the role already has sqs:SendMessage in its identity-based policy. Adding a queue policy does not address why the existing identity-based permission is not taking effect. The root cause is likely a missing or incorrect resource specification, so this action is unnecessary and does not resolve the underlying mismatch.

  • ✗

    Enable AWS CloudTrail data events for the SQS queue and retry the Lambda invocation.

    Why it's wrong here

    CloudTrail data events record API activity such as SendMessage, but they do not grant permissions. Enabling data events only provides an audit trail of the failed and successful calls; it cannot change the authorization decision. The AccessDenied error will persist because the identity-based policy still lacks a valid resource ARN. This action adds observability but does not fix the permission problem.

  • ✗

    Attach the AmazonSQSFullAccess managed policy to the Lambda execution role.

    Why it's wrong here

    AmazonSQSFullAccess grants permissions for every SQS action across all queues, including sqs:DeleteQueue and sqs:CreateQueue. The function only needs to send messages to one specific queue. Applying this managed policy violates least privilege by allowing the role to modify or delete queues, and it could mask the real configuration problem rather than fixing the unnecessarily broad permissions. It resolves the symptom but not with least privilege as the question requires.

  • ✓

    Update the Lambda execution role's identity-based policy to use the SQS queue's ARN as the Resource for the sqs:SendMessage statement.

    Why this is correct

    The execution role's policy must specify the correct ARN of the target SQS queue as the Resource for the sqs:SendMessage action. If the Resource was written incorrectly, for example using the queue URL or a different queue's ARN, the action is implicitly denied. Correcting the Resource to match the queue ARN grants only the required permission on the intended queue, satisfying least privilege while resolving the AccessDenied error.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.