DVA-C02 Troubleshooting and Optimization Practice Question
A developer is debugging an AWS Lambda function that is invoked by an Amazon S3 bucket notification. The function fails with an 'AccessDenied' error when trying to read an object from the same bucket. What should the developer check first?
⚠ Common exam trap
The trap is overthinking encryption or public access blocks, but the most common cause of AccessDenied in Lambda is missing IAM permissions in the execution role.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review the Lambda function's execution role for s3:GetObject permission.
The developer should first review the Lambda function's execution role for s3:GetObject permission. The 'AccessDenied' error indicates the function lacks permission to read the object. The execution role must have an IAM policy granting s3:GetObject on the bucket or object. This is the most direct cause.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Check if S3 bucket versioning is enabled.
Why it's wrong here
S3 bucket versioning is a feature that preserves multiple versions of an object, protecting against accidental deletions or overwrites, and allowing for easy rollback. However, enabling or disabling versioning does not impose any restrictions or grant any additional permissions that would directly affect a Lambda function's ability to perform a basic `s3:GetObject` operation. Therefore, the status of bucket versioning is irrelevant to an 'AccessDenied' error for object retrieval.
- ✗
Verify that the S3 bucket uses server-side encryption with AWS KMS.
Why it's wrong here
While objects encrypted with AWS Key Management Service (KMS) do require the Lambda function's execution role to have `kms:Decrypt` permissions, an 'AccessDenied' error specifically for `s3:GetObject` indicates a primary failure at the S3 permission level. Without the fundamental `s3:GetObject` permission, the Lambda function cannot even initiate the request to retrieve the object, regardless of its encryption status or the presence of KMS decryption permissions.
- ✗
Ensure the S3 bucket is not blocked by S3 Block Public Access.
Why it's wrong here
S3 Block Public Access settings are designed to prevent public and anonymous access to S3 buckets and objects. However, an AWS Lambda function, when configured with an appropriate IAM execution role, accesses S3 as an authorized AWS service principal, not as a public entity. Therefore, these settings would not typically cause an 'AccessDenied' error for a properly authorized Lambda function attempting to read an object.
- ✓
Review the Lambda function's execution role for s3:GetObject permission.
Why this is correct
An 'AccessDenied' error when an AWS Lambda function attempts to interact with Amazon S3 is most commonly caused by insufficient permissions defined in its IAM execution role. To successfully retrieve an object from S3, the Lambda function's execution role must have an IAM policy that explicitly grants the `s3:GetObject` action on the specific target S3 bucket and object path. This is the foundational security control for S3 object retrieval.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.