DVA-C02 Security Practice Question
A developer is creating an IAM policy for a Lambda function that needs to read from an SQS queue and write to a DynamoDB table. Which THREE permissions are required? (Select THREE.)
⚠ Common exam trap
Watch out — candidates often confuse the permissions needed for a Lambda function acting as a consumer (ReceiveMessage and DeleteMessage) with those needed for a producer (SendMessage), or they mistakenly think GetItem is required for writing to DynamoDB when PutItem is the correct write operation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
sqs:DeleteMessage
A is correct because the Lambda function must delete messages from the SQS queue after processing them to prevent them from being reprocessed. The sqs:DeleteMessage permission is required to call the DeleteMessage API, which removes the message from the queue using its receipt handle. Without this permission, the function would successfully receive and process the message but fail to delete it, causing the message to become visible again after the visibility timeout expires.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
sqs:DeleteMessage
Why this is correct
This permission is essential for a Lambda function processing messages from an SQS queue. After a message is successfully processed, the function must explicitly call `DeleteMessage` to remove it from the queue. Without this action, the message will eventually become visible again after its visibility timeout expires, leading to duplicate processing and potential data inconsistencies, which is critical to avoid for reliable message handling.
- ✓
dynamodb:PutItem
Why this is correct
The `dynamodb:PutItem` permission is necessary when the Lambda function's logic involves storing new data or updating existing items within an Amazon DynamoDB table. This action allows the function to write a complete item, identified by its primary key, into the specified table. It is fundamental for persistence operations where the function needs to record its processing results or new information into a database.
- ✓
sqs:ReceiveMessage
Why this is correct
To retrieve messages from an Amazon SQS queue for processing, the `sqs:ReceiveMessage` permission is absolutely required. This action allows the Lambda function to poll the queue and fetch one or more messages, making them temporarily invisible to other consumers during the processing window. It is the foundational capability for any Lambda function designed to consume and react to SQS events.
- ✗
sqs:SendMessage
Why it's wrong here
The `sqs:SendMessage` permission is not required for a Lambda function whose primary task is to process messages received from an SQS queue and write data to DynamoDB. This action is used for publishing messages *to* an SQS queue, which is an outbound communication pattern not indicated by the problem description. The function's role as a consumer and data writer does not inherently necessitate sending new messages back into SQS.
- ✗
dynamodb:GetItem
Why it's wrong here
The `dynamodb:GetItem` permission is not necessary for a Lambda function focused on *writing* items to DynamoDB, as implied by the `PutItem` requirement. This action is specifically used to retrieve a single item from a DynamoDB table based on its primary key, representing a read operation. Since the function's stated purpose revolves around storing data, not querying it, this read-specific permission is extraneous for its core functionality.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.