Courseiva
Security →easyMultiple Choice

DVA-C02 Security Practice Question

A developer needs to grant least-privilege access to a Lambda function to write logs to CloudWatch Logs. Which IAM policy effect should be used?

⚠ Common exam trap

DVA-C02 often tests IAM policy syntax basics, and the trap is that candidates overthink the question and look for a special effect, when the only valid granting effect is Allow.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Allow

IAM policies use the Effect element with valid values of Allow or Deny; to grant least-privilege access, the policy statement must specify Effect: Allow with the specific action logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents scoped to the function's log group. Allow is the only effect that grants permissions in an identity-based policy. Deny would explicitly block the action, which is the opposite of the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Always allow

    Why it's wrong here

    IAM policy statements recognize only two effect values, Allow and Deny; 'Always allow' is not part of the IAM policy grammar and would cause the policy document to fail validation if used, so it cannot be selected as a real effect.

  • ✓

    Allow

    Why this is correct

    Allow is the correct IAM policy effect for least-privilege access because it explicitly grants only the specific actions listed, such as logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents, scoped to the exact CloudWatch Logs resource ARNs the Lambda function needs, without granting any broader access.

  • ✗

    Deny

    Why it's wrong here

    Deny is a valid IAM effect, but it is used to explicitly block access to actions or resources, often to override a broader Allow from another attached policy; it cannot be used to grant the Lambda function permission to write logs, so it does not satisfy the requirement here.

  • ✗

    Revoke

    Why it's wrong here

    Revoke does not exist as an IAM policy effect at all; permissions in IAM are removed by detaching or deleting policies or by adding an explicit Deny statement, not by a 'Revoke' keyword within a policy document.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.