DVA-C02 Security Practice Question
A developer is building a serverless order-processing application. An AWS Lambda function must read records from an Amazon DynamoDB table and write audit entries to an Amazon SQS queue. The developer creates the Lambda execution role and attaches a managed policy that grants dynamodb:GetItem, dynamodb:PutItem, sqs:SendMessage, and logs:CreateLogGroup permissions on the specific resources. After deployment, the Lambda function successfully reads and writes to DynamoDB, but every attempt to send a message to the SQS queue fails with an AccessDenied error. The developer confirms the SQS queue URL in the code is correct and the queue exists in the same AWS Region. Which action will resolve this issue with the LEAST privilege?
⚠ Common exam trap
The trap here is assuming that any AccessDenied error means the action is missing from the policy, when in fact the action is present but scoped to the wrong resource ARN.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Update the Lambda execution role's identity-based policy to use the SQS queue's ARN as the Resource for the sqs:SendMessage statement.
The Lambda execution role already includes the sqs:SendMessage action, so the denial is caused by the Resource element not matching the target queue's ARN. AWS evaluates identity-based policies by matching the requested resource against the Resource element; a mismatch results in an implicit deny. Correcting the Resource to the queue's ARN grants exactly the needed permission on the intended queue, which resolves the error while honoring least privilege.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add a resource-based policy to the SQS queue that allows the Lambda execution role to call sqs:SendMessage.
Why it's wrong here
SQS queue policies are resource-based policies that grant access to principals, and they can allow a role to send messages. However, in this scenario the role already has sqs:SendMessage in its identity-based policy. Adding a queue policy does not address why the existing identity-based permission is not taking effect. The root cause is likely a missing or incorrect resource specification, so this action is unnecessary and does not resolve the underlying mismatch.
- ✗
Enable AWS CloudTrail data events for the SQS queue and retry the Lambda invocation.
Why it's wrong here
CloudTrail data events record API activity such as SendMessage, but they do not grant permissions. Enabling data events only provides an audit trail of the failed and successful calls; it cannot change the authorization decision. The AccessDenied error will persist because the identity-based policy still lacks a valid resource ARN. This action adds observability but does not fix the permission problem.
- ✗
Attach the AmazonSQSFullAccess managed policy to the Lambda execution role.
Why it's wrong here
AmazonSQSFullAccess grants permissions for every SQS action across all queues, including sqs:DeleteQueue and sqs:CreateQueue. The function only needs to send messages to one specific queue. Applying this managed policy violates least privilege by allowing the role to modify or delete queues, and it could mask the real configuration problem rather than fixing the unnecessarily broad permissions. It resolves the symptom but not with least privilege as the question requires.
- ✓
Update the Lambda execution role's identity-based policy to use the SQS queue's ARN as the Resource for the sqs:SendMessage statement.
Why this is correct
The execution role's policy must specify the correct ARN of the target SQS queue as the Resource for the sqs:SendMessage action. If the Resource was written incorrectly, for example using the queue URL or a different queue's ARN, the action is implicitly denied. Correcting the Resource to match the queue ARN grants only the required permission on the intended queue, satisfying least privilege while resolving the AccessDenied error.
Visual reference
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.