Courseiva

DVA-C02 Troubleshooting and Optimization Practice Question

A developer is troubleshooting an AWS Lambda function that writes to an S3 bucket. The function is configured with a resource-based policy that allows the S3 service to invoke the function. However, the function fails with an access denied error when trying to write to S3. What is the MOST likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Lambda function's execution role does not have an IAM policy that allows s3:PutObject.

The Lambda function's execution role lacks the necessary IAM permissions (s3:PutObject) to write to the S3 bucket. The resource-based policy only allows S3 to invoke the function, not the function to write. Option A is incorrect because a VPC endpoint would not cause an access denied error for writing if the execution role had permissions. Option C is incorrect because trigger misconfiguration would prevent invocation, not cause access denied during execution. Option D is incorrect because the S3 bucket policy is not required if the execution role grants write access; the bucket policy controls who can access the bucket, but the execution role is the primary mechanism for Lambda permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Lambda function is configured in a VPC without an S3 VPC endpoint.

    Why it's wrong here

    If a Lambda function configured within a Virtual Private Cloud (VPC) attempts to access public AWS services like S3 without a NAT Gateway or a VPC endpoint for S3, its network requests will fail to route outside the VPC. This network misconfiguration would typically manifest as a connection timeout error, as the function cannot establish communication with the S3 service. It would not result in an "Access Denied" error, which indicates a successful connection but a lack of authorization from the service itself.

  • ✓

    The Lambda function's execution role does not have an IAM policy that allows s3:PutObject.

    Why this is correct

    The Lambda function's execution role is the IAM identity that the function assumes when it runs, dictating what AWS services and resources it is authorized to interact with. If this execution role lacks an IAM policy that explicitly grants the s3:PutObject permission, any attempt by the function to write or upload an object to an S3 bucket will be rejected by AWS Identity and Access Management (IAM). This directly leads to an "Access Denied" error, as the function is not authorized to perform that specific action.

  • ✗

    The Lambda function's trigger (S3 event notification) is misconfigured.

    Why it's wrong here

    A misconfigured S3 event notification would prevent the Lambda function from being invoked altogether when an object is uploaded to the S3 bucket. Since the problem describes the function encountering an "Access Denied" error during its execution, it implies that the function was successfully invoked and began running. Therefore, the S3 trigger mechanism itself is functioning correctly, and the issue lies within the function's runtime permissions or code, not its invocation.

  • ✗

    The S3 bucket policy does not grant the Lambda function write access.

    Why it's wrong here

    While S3 bucket policies can grant or deny access to a bucket, the primary mechanism for a Lambda function to gain permissions to interact with S3 within the same account is through its IAM execution role. If the execution role already possesses the necessary s3:PutObject permission, a separate bucket policy granting the same access is often redundant. Conversely, if the execution role *lacks* the permission, the bucket policy alone cannot grant it, unless the bucket policy explicitly allows the Lambda service principal or the specific role ARN, which is less common for internal function permissions than relying on the execution role.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.