Courseiva

DVA-C02 Development with AWS Services Practice Question

A developer is deploying a serverless application using the AWS Serverless Application Model (SAM). The application includes an API Gateway REST API and a Lambda function. The developer wants to enable access logging for the API Gateway. Which THREE resources or configurations are required? (Choose THREE.)

⚠ Common exam trap

A common mix-up: candidates confuse the IAM role needed for API Gateway to write logs (Option C) with the Lambda execution role (Option E), or incorrectly think a Lambda function must process the logs (Option B) when API Gateway writes them directly to CloudWatch Logs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A stage with access logging enabled in the API Gateway.

API Gateway access logging is configured at the stage level. The developer must enable access logging on a specific stage (e.g., prod, dev) and specify a destination CloudWatch Logs log group and a logging format (e.g., JSON or CLF). Without enabling it on the stage, no access logs are generated regardless of other configurations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A stage with access logging enabled in the API Gateway.

    Why this is correct

    Enabling access logging on a specific API Gateway stage is a fundamental configuration step for capturing API traffic. This setting dictates that API Gateway will generate detailed information about every request and response passing through that stage, including caller IP, request latency, and response status. Without this explicit enablement on the stage, no access logs will be generated, regardless of other logging infrastructure being in place. Therefore, it is a prerequisite for any access logging functionality.

  • ✗

    A Lambda function that processes the access logs.

    Why it's wrong here

    A Lambda function is not a prerequisite for API Gateway to generate and send access logs to CloudWatch Logs. API Gateway directly integrates with CloudWatch Logs for this purpose, eliminating the need for an intermediary compute service to collect or forward the raw access data. While a Lambda function could be used *after* logs are in CloudWatch to process, analyze, or forward them to another destination, it is not part of the initial setup for enabling API Gateway access logging itself.

  • ✓

    An IAM role that grants API Gateway permission to write to CloudWatch Logs.

    Why this is correct

    An IAM role is absolutely essential for API Gateway to have the necessary permissions to interact with CloudWatch Logs. This role must grant specific actions such as `logs:CreateLogGroup`, `logs:CreateLogStream`, and `logs:PutLogEvents` to allow API Gateway to create log resources and write log entries. Without an appropriately configured IAM role, API Gateway will lack the authorization to publish any access logs to the designated CloudWatch Logs log group, resulting in logging failures.

  • ✓

    An Amazon CloudWatch Logs log group.

    Why this is correct

    An Amazon CloudWatch Logs log group serves as the designated destination for API Gateway access logs. This log group acts as a centralized repository where all the captured request and response details are stored securely and durably. It provides the necessary structure for log retention, monitoring, and subsequent analysis using CloudWatch Logs Insights or other integrated AWS services, making it a critical component for any comprehensive logging strategy.

  • ✗

    An IAM role for the Lambda function with logs:PutLogEvents permission.

    Why it's wrong here

    An IAM role for a Lambda function, even with `logs:PutLogEvents` permission, is irrelevant for enabling API Gateway access logging. This specific role governs the permissions for the *Lambda function itself* to write its own operational logs to CloudWatch Logs, not for API Gateway to write its access logs. API Gateway requires its *own* dedicated IAM role to publish access logs, separate from any backend integration's permissions or the permissions of the integrated Lambda function.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.