DVA-C02 Troubleshooting and Optimization Practice Question
A developer is using an Amazon SQS queue with a Lambda function as a consumer. Messages are being sent to the queue but the Lambda function is not processing them. Which THREE of the following are possible causes?
⚠ Common exam trap
The trap here is that candidates often overlook resource-based policies (like SQS queue policies) and focus only on the Lambda execution role, assuming that if the role has permissions, the integration will work, but the queue policy can independently deny access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The SQS queue policy denies access to the Lambda function.
The SQS queue policy is a resource-based policy that controls which principals (like Lambda's execution role) can perform actions on the queue. If the policy explicitly denies the Lambda function's access, the function will not be able to poll or delete messages from the queue, even if its own execution role grants those permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The SQS queue has a dead-letter queue configured.
Why it's wrong here
A dead-letter queue (DLQ) is designed to store messages that a consumer, such as a Lambda function, failed to process successfully after a specified number of retries (the maxReceiveCount). Its purpose is to isolate problematic messages for later analysis, not to prevent the Lambda function from initially receiving messages from the source queue. Therefore, configuring a DLQ would not stop the Lambda function from attempting to poll and process messages from the primary queue.
- ✓
The SQS queue policy denies access to the Lambda function.
Why this is correct
An SQS queue policy is a resource-based policy that defines who can access the queue and what actions they can perform. If this policy contains an explicit Deny statement for the sqs:ReceiveMessage action (or other relevant polling actions) for the Lambda function's execution role, the Lambda service will be unable to poll messages from the queue. This explicit denial takes precedence over any Allow statements in the Lambda's IAM role, effectively blocking access.
- ✓
The Lambda function's execution role does not have sqs:ReceiveMessage permission.
Why this is correct
The Lambda function's execution role dictates the permissions that the Lambda service assumes when executing the function and interacting with other AWS services. For a Lambda function to poll messages from an SQS queue, its execution role must explicitly grant the sqs:ReceiveMessage, sqs:DeleteMessage, and sqs:GetQueueAttributes permissions. Lacking the essential sqs:ReceiveMessage permission directly prevents the Lambda service from pulling messages from the queue, thus stopping message processing.
- ✗
The SQS queue has a rate limit that prevents Lambda from polling.
Why it's wrong here
Amazon SQS is designed for high throughput and does not impose explicit rate limits on polling requests from consumers like Lambda functions. While there are service quotas for API calls, SQS automatically scales to accommodate a very large number of concurrent ReceiveMessage requests. Therefore, a "rate limit" preventing Lambda from polling is not a standard SQS feature and would not be the cause of the issue.
- ✓
The event source mapping between SQS and Lambda is disabled.
Why this is correct
An event source mapping is the configuration that tells the Lambda service to poll a specific SQS queue for messages and invoke the associated Lambda function. If this event source mapping is disabled, the Lambda service will cease polling the SQS queue entirely, effectively stopping all message processing. It acts as the on/off switch for the integration, directly preventing the function from receiving messages.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.