DVA-C02 Security Practice Question
A developer is using AWS Lambda to process files uploaded to an S3 bucket. The Lambda function needs to write logs to CloudWatch Logs. Which of the following is required to allow this?
⚠ Common exam trap
DVA-C02 often tests the misconception that Lambda automatically has permissions to write to CloudWatch Logs or that a separate role for CloudWatch Logs is needed, when in fact the execution role must be explicitly granted those permissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach an IAM policy to the Lambda execution role with CloudWatch Logs permissions
The Lambda execution role is the IAM role that Lambda assumes when the function runs, and it defines what AWS services and resources the function can access. To write logs to CloudWatch Logs, the execution role must have an IAM policy attached that grants permissions for actions like logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents. Without these permissions, the function cannot write logs, even if it has the necessary code. Therefore, attaching an IAM policy to the Lambda execution role with CloudWatch Logs permissions is required.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Attach an IAM policy to the Lambda execution role with CloudWatch Logs permissions
Why this is correct
Attaching an IAM policy with CloudWatch Logs permissions to the Lambda execution role is the correct approach. The Lambda execution role defines the permissions that the function itself has when interacting with other AWS services. For a Lambda function to successfully send its logs (e.g., from `console.log` or `print` statements) to CloudWatch Logs, this role must explicitly grant actions like `logs:CreateLogGroup`, `logs:CreateLogStream`, and `logs:PutLogEvents` to the relevant CloudWatch Logs resources.
- ✗
Add a resource-based policy to the Lambda function
Why it's wrong here
Adding a resource-based policy to the Lambda function is incorrect for granting the function permissions to log. Resource-based policies are used to grant other AWS services or accounts permission to invoke the Lambda function itself. For example, an S3 bucket uses a resource-based policy to allow it to trigger a Lambda function upon an object upload. These policies do not define what permissions the Lambda function has to interact with other AWS services like CloudWatch Logs.
- ✗
Configure the S3 bucket to trigger Lambda, and Lambda automatically logs to CloudWatch
Why it's wrong here
Configuring an S3 bucket to trigger a Lambda function only establishes the event source for invocation, it does not automatically grant the Lambda function logging capabilities. AWS Lambda functions do not inherently log to CloudWatch without explicit permissions. Regardless of how a Lambda function is invoked, its associated IAM execution role must possess the necessary CloudWatch Logs permissions to create log groups, create log streams, and publish log events.
- ✗
Create an IAM role for CloudWatch Logs and assign it to the Lambda function
Why it's wrong here
Creating a separate IAM role specifically for CloudWatch Logs and attempting to assign it to the Lambda function is not how Lambda's permission model works. A Lambda function is associated with a single IAM execution role, which consolidates all permissions the function needs to perform its tasks, including interacting with CloudWatch Logs. You cannot assign multiple, distinct IAM roles to a single Lambda function for different purposes; all required permissions must be included within the policy of its sole execution role.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.