DVA-C02 Security Practice Question
A developer needs to grant least-privilege access to a Lambda function to write logs to CloudWatch Logs. Which IAM policy effect should be used?
⚠ Common exam trap
DVA-C02 often tests IAM policy syntax basics, and the trap is that candidates overthink the question and look for a special effect, when the only valid granting effect is Allow.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Allow
IAM policies use the Effect element with valid values of Allow or Deny; to grant least-privilege access, the policy statement must specify Effect: Allow with the specific action logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents scoped to the function's log group. Allow is the only effect that grants permissions in an identity-based policy. Deny would explicitly block the action, which is the opposite of the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Always allow
Why it's wrong here
IAM policy statements recognize only two effect values, Allow and Deny; 'Always allow' is not part of the IAM policy grammar and would cause the policy document to fail validation if used, so it cannot be selected as a real effect.
- ✓
Allow
Why this is correct
Allow is the correct IAM policy effect for least-privilege access because it explicitly grants only the specific actions listed, such as logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents, scoped to the exact CloudWatch Logs resource ARNs the Lambda function needs, without granting any broader access.
- ✗
Deny
Why it's wrong here
Deny is a valid IAM effect, but it is used to explicitly block access to actions or resources, often to override a broader Allow from another attached policy; it cannot be used to grant the Lambda function permission to write logs, so it does not satisfy the requirement here.
- ✗
Revoke
Why it's wrong here
Revoke does not exist as an IAM policy effect at all; permissions in IAM are removed by detaching or deleting policies or by adding an explicit Deny statement, not by a 'Revoke' keyword within a policy document.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.